CVE-2026-85532
Received Received - Intake

Apache WSS4J Derived-Key Length Validation Flaw

Vulnerability report for CVE-2026-85532, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Apache Software Foundation

Description

Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages. The fixes enforce a minimum key length of 16 bytes, a maximum length of 512 bytes, and a maximum offset of 4096 bytes. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
apache wss4j From 4.0.2 (inc)
apache wss4j From 3.0.6 (inc)
apache wss4j From 2.4.4 (inc)
apache wss4j 4.0.2
apache wss4j 3.0.6
apache wss4j 2.4.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without proper validation. This could allow weak cryptographic keys or cause excessive CPU and memory usage when processing specially crafted WS-Security messages. The issue was fixed by enforcing minimum and maximum key lengths and offsets.

Impact Analysis

An attacker could exploit this to create weak encryption keys, potentially decrypting sensitive data. It could also cause denial-of-service by consuming excessive system resources when processing malicious messages.

Compliance Impact

This vulnerability could lead to unauthorized data access or disclosure, violating GDPR's data protection requirements or HIPAA's security rules for protected health information. Weak encryption may fail compliance checks for data integrity and confidentiality.

Mitigation Strategies

Upgrade Apache WSS4J to a fixed version: 4.0.2 or later, 3.0.6 or later, or 2.4.4 or later. This addresses the derived-key length and offset validation issues.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85532. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart