CVE-2026-89238

NameCVE-2026-89238
DescriptionWSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
wss4j (PTS)bookworm1.6.19-3vulnerable
forky, sid, trixie1.6.19-4vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
wss4jsource(unstable)(unfixed)

Notes

https://lists.apache.org/thread.html/1lv4hpl8kon1ns5txjnhn2m2sh9rl22w

Search for package or bug name: Reporting problems