Skip to content
Rota Nacional

Cyber ·

CVE-2026-92899: Apache WSS4J flaw

A notice published on September 30, 2026 describes how differing Base64 representations of a Nonce can bypass UsernameToken replay protection in Apache WSS4J. The stated severity is moderate.

The CVE-2026-92899 notice says Apache WSS4J tracks the Nonce of each accepted UsernameToken to prevent a captured token from being reused. The flaw arises because the value is stored as raw Base64 text, while authentication compares the decoded bytes. The same bytes can have different Base64 representations, potentially bypassing the replay check. The stated severity is moderate.

According to the notice, WSS4J versions before 4.0.2 in the 4.0 series, before 3.0.6 in the 3.0 series, and before 2.4.4 are affected. Consult the original notice in the oss-sec feed to verify its scope and details; compare installed versions with the stated fixed releases and validate any update in your environment. If using AI to study the notice or plan an update, do not submit credentials or unnecessary personal data.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free