DEVELOPERS have disclosed six critical vulnerabilities in Apache WSS4J, prompting a call to urgent action for administrators. The flaws affect the WS-Security library across multiple release lines and include authentication bypass and denial-of-service risks. The most severe entry is CVE-2026-88920, with a CVSSv3 score of 9.8, which would allow remote attackers to forge authenticated messages.
The update notes indicate patched releases are 4.0.2, 3.0.6 and 2.4.4, which should be applied immediately to mitigate all six defects. At present, researchers report no public proof-of-concept exploit code and no confirmed exploitation in the wild, but unpatched servers remain at high risk of message forgery and memory exhaustion.
The article explains that the vulnerabilities arise from distinct XML parsing and cryptographic validation routines within WSS4J. CVE-2026-88920 involves an authentication bypass in the DOM security processor, where a crafted unsigned SAML sender-vouches assertion could be accepted as valid. CVE-2026-95616 centers on an integer overflow in the DER bounds checker, potentially triggering a two-gigabyte memory allocation and a denial of service.
Other flaws permit issues such as nonce replay, misplacement of decrypted headers, and XML Signature Wrapping, among others. Affected versions are all library releases prior to 4.0.2, 3.0.6, and 2.4.4. organisations should obtain the patched libraries from the Apache WSS4J download page and update dependencies to restore secure authentication and protect against memory‑related attacks.