CVE-2026-87830 PUBLISHED

Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks.

Assigner: apache
Reserved: 09.09.2026 Published: 30.09.2026 Updated: 30.09.2026

In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

Product Status

Vendor Apache Software Foundation
Product Apache WSS4J
Versions Default: unaffected
  • affected from 4.0.0 to 4.0.2 (excl.)
  • affected from 3.0.0 to 3.0.6 (excl.)
  • affected from 0 to 2.4.4 (excl.)

Credits

  • Reported by n0mi1k finder

References