Sceawere

Vulnerability Detail

CVE-2026-95616UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WSS4J Integer Overflow Memory Exhaustion

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
Apache Software Foundation
Product
Apache WSS4J
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-30T13:17:28.863Z",
  "pubdate": "2026-09-30T13:17:28.863Z",
  "executiveSummary": "WSS4J is susceptible to a heap-based memory exhaustion vulnerability originating from an integer overflow within its DER (Distinguished Encoding Rules) bounds checking logic.\nThe vulnerability allows an unauthenticated remote attacker to trigger massive memory allocations by sending a specially crafted SOAP message containing a malicious X.509 certificate.\nBy manipulating the SubjectKeyIdentifier extension length to 0x7FFFFFFF, the attacker induces the application to allocate 2 GB of memory per request, leading to rapid Denial of Service (DoS) through resource exhaustion.\nThis flaw is particularly critical because the malicious decoding occurs during the signature key reference resolution phase, which precedes the authentication of the SOAP message.\nConsequently, the system is exposed to external network traffic, and an attacker does not require valid credentials or authorized access to exploit this vector.\nThe risk profile is significant as it facilitates a low-complexity DoS attack that can effectively destabilize any exposed WSS4J-based web service.",
  "technicalDetails": "The root cause of this vulnerability lies in an improper integer overflow check within the DER decoding process of the WSS4J security library. When WSS4J processes a SOAP message, it must resolve key references found within the security headers, specifically when parsing X.509 certificates.\nDuring the parsing of the SubjectKeyIdentifier extension, the library fails to adequately validate the length field provided within the DER-encoded ASN.1 structure. An attacker crafts an X.509 certificate extension where the declared length is set to 0x7FFFFFFF (the maximum signed 32-bit integer).\nBecause the bounds checking logic does not correctly account for the potential overflow during the allocation calculation, the library accepts the malicious length value despite the actual extension data being significantly smaller (e.g., eleven bytes).\nThe attack flow proceeds as follows: First, the attacker transmits a SOAP message containing the malformed certificate to an endpoint protected by WSS4J. Second, the WSS4J engine interceptor processes the security header to perform signature verification. Third, during the resolution of the key identifier, the library invokes the vulnerable DER decoding routine. Fourth, the library calculates an allocation size based on the malicious 0x7FFFFFFF value. Fifth, the system attempts to allocate 2 GB of heap memory for the extension data. Sixth, the underlying JVM performs this allocation before the message is ever cryptographically authenticated.\nBy repeating this process multiple times, an attacker can rapidly exhaust the available server heap memory, leading to an OutOfMemoryError, severe performance degradation, or an application crash. Since this processing occurs before the message is authenticated, the attacker requires no privilege level or valid session tokens. This vulnerability affects WSS4J versions prior to 4.0.2, 3.0.6, and 2.4.4, rendering any system integrating these versions vulnerable to network-based DoS attacks if they process untrusted XML signatures."
}
CVE-2026-95616: WSS4J Integer Overflow Memory Exhaustion (HIGH Severity, CVSS: 7.5) | Sceawere