Vulnerabilities
Summary — last 7 days
New vulnerabilities3,338▲ 363 vs. last week
Critical / high1,493▲ 135 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 119 vs. last week
11 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | High (7.5) | — | — | Apache Wss4jAI | 9/30/2026 | 9/30/2026 | An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before… | |
| Undergoing Analysis | Medium (4.8) | — | — | Apache Wss4jAI | 9/30/2026 | 9/30/2026 | Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could… | |
| Awaiting Analysis | High (7.5) | — | — | Apache Wss4jAI | 9/30/2026 | 9/30/2026 | In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, so it stops evaluating SignedParts and SignedElements for the rest of… | |
| Awaiting Analysis | Critical (9.1) | — | — | Apache Wss4jAI | 9/30/2026 | 9/30/2026 | WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. | |
| Undergoing Analysis | Critical (9.8) | — | — | Apache Wss4jAI | 9/30/2026 | 9/30/2026 | An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix… | |
| Undergoing Analysis | High (7.5) | — | — | Apache Wss4jAI | 9/30/2026 | 9/30/2026 | Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages. The fixes enforce a minimum key length of 16 bytes, a maximum length of 512 bytes, and a… | |
| Modified | High (8.8) | 23% | — | Apache Velocity EngineApache Wss4jDebian LinuxOracle Banking Deposits AND Lines OF Credit Servicing+12 | 3/10/2021 | 6/17/2026 | An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine… | |
| Modified | Medium (5.9) | 1.8% | — | Apache CXFApache Wss4jRedhat Jboss Business Rules Management SystemRedhat Jboss Enterprise Application Platform+6 | 3/11/2020 | 6/16/2026 | The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack. | |
| Modified | High (7.5) | 5.5% | — | Apache Wss4j | 10/30/2017 | 6/17/2026 | Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists… | |
| Modified | Medium (5) | 7.5% | — | Apache Wss4j | 2/12/2015 | 6/17/2026 | Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks." | |
| Modified | Medium (5) | 9.2% | — | Apache Wss4jApache CXF | 10/30/2014 | 6/17/2026 | Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors. |