Information on source package wss4j

Available versions

ReleaseVersion
bookworm1.6.19-3
trixie1.6.19-4
forky1.6.19-4
sid1.6.19-4

Open issues

BugbookwormtrixieforkysidDescription
CVE-2026-95616vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablevulnerableAn integer overflow in WSS4J's DER bounds check lets an oversized allo ...
CVE-2026-92899vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablevulnerableApache WSS4J remembers the Nonce of each UsernameToken it accepts, so ...
CVE-2026-92121fixedvulnerable (no DSA)vulnerablevulnerableIn the WSS4J streaming (StAX) code, a signature reference using the WS ...
CVE-2026-89238vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablevulnerableWSS4J EncryptedHeader child confusion could promote an attacker-contro ...
CVE-2026-88920vulnerable (no DSA, ignored)vulnerable (no DSA)vulnerablevulnerableAn authentication bypass in the DOM security processor in Apache WSS4J ...
CVE-2026-87830fixedvulnerable (no DSA)vulnerablevulnerableIn the StAX streaming WS-SecurityPolicy validator, certain relative or ...
CVE-2026-85532vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablevulnerableApache WSS4J accepted attacker-controlled derived-key lengths and offs ...

Resolved issues

BugDescription
CVE-2015-0227Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attacker ...
CVE-2015-0226Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks inf ...

Search for package or bug name: Reporting problems