| Bug | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-95616 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable | vulnerable | An integer overflow in WSS4J's DER bounds check lets an oversized allo ... |
| CVE-2026-92899 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable | vulnerable | Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so ... |
| CVE-2026-92121 | fixed | vulnerable (no DSA) | vulnerable | vulnerable | In the WSS4J streaming (StAX) code, a signature reference using the WS ... |
| CVE-2026-89238 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable | vulnerable | WSS4J EncryptedHeader child confusion could promote an attacker-contro ... |
| CVE-2026-88920 | vulnerable (no DSA, ignored) | vulnerable (no DSA) | vulnerable | vulnerable | An authentication bypass in the DOM security processor in Apache WSS4J ... |
| CVE-2026-87830 | fixed | vulnerable (no DSA) | vulnerable | vulnerable | In the StAX streaming WS-SecurityPolicy validator, certain relative or ... |
| CVE-2026-85532 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable | vulnerable | Apache WSS4J accepted attacker-controlled derived-key lengths and offs ... |