VYPR
High severity7.5NVD Advisory· Published Sep 30, 2026· Updated Sep 30, 2026

CVE-2026-95616

CVE-2026-95616

Description

An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1
  • Apache/Wss4jllm-fuzzy
    Range: up to 4.0.2, 3.0.6, or 2.4.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.