A security notice published on September 30, 2026 describes CVE-2026-87830 in Apache WSS4J. According to the text, certain relative or unsupported XPath expressions may be converted into paths that never match elements during streaming StAX validation of WS-SecurityPolicy.
The notice rates the severity as low. The affected versions listed are the wss4j-ws-security-policy-stax module: 4.0.0 before 4.0.2, 3.0.0 before 3.0.6, and versions before 2.4.4. The available excerpt does not provide further remediation details or describe mitigation steps.
To assess exposure, identify the exact module version in your dependencies and confirm whether the service uses this streaming validation. Compare your findings with the official Apache notice and the project’s security records; do not infer that an installation is vulnerable from the product name alone.
Before changing dependencies, test the update in a controlled environment and check the relevant WS-Security policies. If you use AI to study the notice or analyze configurations, share only what is necessary and remove personal data, credentials, and sensitive internal details.