Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-92121

CVE-2026-92121: 1 tracked advisory record across Apache. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Apache

1 advisory
  • Advisory severityHigh7.5

    High [CVE-2026-92121] In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set

    CVE-2026-92121Source published Source updated

    In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, so it stops evaluating SignedParts and SignedElements for the rest of the message. A policy requiring the SOAP Body to be signed is then satisfied even when the Body carries no signature, removing the protection against XML Signature Wrapping. Signature verification itself is unaffected. The DOM code is not affected. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4 which fix this issue. Affected product named by the advisory: Apache WSS4J.

    Related products — impact not confirmed
    • Apache WSS4J
    Source-reported affected versions
    • Apache WSS4J 4.0.0 before 4.0.2
    • Apache WSS4J 3.0.0 before 3.0.6
    • Apache WSS4J before 2.4.4
    Source-reported fixed versions
    • 4.0.2
    • 3.0.6
    • 2.4.4
    Mitigation guidance
    • Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4 which fix this issue.

Android app · Google Play

Monitor future Apache CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery