Skip to content
Rota Nacional

Cyber ·

CVE-2026-85532: Apache WSS4J validation flaw

An advisory published on September 30, 2026 reports insufficient validation of derived-key parameters, with moderate severity and a risk of weak keys or excessive CPU use.

An oss-sec feed notice, published on September 30, 2026 and presented as an automatic translation, reports CVE-2026-85532 in Apache WSS4J. The stated severity is moderate. The affected component is org.apache.wss4j:wss4j-ws-security-common, in versions 4.0.0 before 4.0.2, 3.0.0 before 3.0.6, and 2.x before 2.4.4.

According to the notice, attacker-controlled derived-key lengths and offsets were not subject to adequate limits, potentially resulting in cryptographically weak keys or excessive CPU use. The supplied excerpt ends before providing further details. Consult the original oss-sec notice and confirm the version, impact, and remediation guidance through official project channels before taking action.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free