The alert, published on September 30, 2026 in the oss-sec feed, describes a flaw in Apache WSS4J streaming (StAX) code. A signature reference using WS-Security STR-Transform may permanently leave the internal “signed content” flag enabled, allowing signature checks to be bypassed. The stated severity is moderate.
Affected versions are in the wss4j-ws-security-stax component: the 4.0 line before 4.0.2; the 3.0 line before 3.0.6; and versions before 2.4.4. The supplied text does not detail exploitation conditions or additional impact.
Consult the original notice in the oss-sec feed and compare the version in your dependency inventory with the stated ranges. Since the available text is an automated translation and ends with an ellipsis, review the complete notice and Apache WSS4J’s official notes before deciding on an update or mitigation.
If using AI to summarize the notice or support triage, share only necessary excerpts and remove names, credentials, and internal data. Verify technical conclusions against official sources and your organization’s security process.