← All Advisories

CVE-2026-85532

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-85532

Key Details

CVECVE-2026-85532
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsApache wss4j and Apache Software Foundation Apache WSS4J
Classified asCWE-20 (Improper Input Validation)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Apachewss4j
Apache Software FoundationApache WSS4J
SubsystemsGeneral OT
SectorsMultiple

What to Know

Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages. The fixes enforce a minimum key length of 16 bytes, a maximum length of 512 bytes, and a maximum offset of 4096 bytes.

Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. (NVD)

What to Do

Monitor Apache's and Apache Software Foundation's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-85532
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-85532
Vendor advisoryhttps://lists.apache.org/thread.html/7jllcpbf4nbzhdp2vchz5yplnl5w6vd6