Status: UPDATED | Advisory ID: CVE-2026-85532
| CVE | CVE-2026-85532 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-10-02 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high. |
| Affected products | Apache wss4j and Apache Software Foundation Apache WSS4J |
| Classified as | CWE-20 (Improper Input Validation) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Apache | wss4j | ||
| Apache Software Foundation | Apache WSS4J |
| Subsystems | General OT |
| Sectors | Multiple |
Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages. The fixes enforce a minimum key length of 16 bytes, a maximum length of 512 bytes, and a maximum offset of 4096 bytes.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. (NVD)
Monitor Apache's and Apache Software Foundation's web pages for any future patch releases. See vendor advisory link below.