CVE-2026-89238 PUBLISHED

Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selection

Assigner: apache
Reserved: 11.09.2026 Published: 30.09.2026 Updated: 30.09.2026

WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

Product Status

Vendor Apache Software Foundation
Product Apache WSS4J
Versions Default: unaffected
  • affected from 4.0.0 to 4.0.2 (excl.)
  • affected from 3.0.0 to 3.0.6 (excl.)
  • affected from 0 to 2.4.4 (excl.)

Credits

  • Reported by n0mi1k finder

References