A notice published on September 30, 2026, reports that confusion among EncryptedHeader child elements may cause Apache WSS4J to treat attacker-controlled content as a decrypted header.
A notice in the oss-sec feed, published by Colm O hEigeartaigh on September 30, 2026, rates CVE-2026-89238 in Apache WSS4J as important. According to the text, confusion among EncryptedHeader child elements may cause WSS4J to promote attacker-controlled plaintext content to a decrypted header, resulting in incorrect confidentiality coverage.
The notice lists the org.apache.wss4j:wss4j-ws-security-dom component as affected in versions 4.0.0 before 4.0.2, 3.0.0 before 3.0.6, and versions before 2.4.4. The supplied content is an automatic translation, and its description is truncated. To confirm the scope and details, consult the original notice in the oss-sec feed and check version and fix information in Apache WSS4J project releases.