A security bulletin dated September 30, 2026 describes CVE-2026-95616 in Apache WSS4J. The text is an automatic translation of a post on the oss-sec feed; consult the original advisory to confirm details and any later updates.
According to the report, an integer overflow in DER bounds checking may allow an excessively large allocation to pass validation. An unauthenticated attacker could send a SOAP message with an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF, causing denial of service when the extension is decoded.
The bulletin rates the severity as important. It lists WSS4J 4.0.0 before 4.0.2, 3.0.0 before 3.0.6, and versions before 2.4.4 as affected. Compare these ranges with your organization’s inventory and confirm in the original advisory which fixed versions apply to your environment.
To verify the report, locate the CVE and consult the original oss-sec post, checking its date, versions, and technical description; the feed translation may not reflect later revisions. If you use AI to summarize or apply the material, submit only necessary excerpts and remove internal data, credentials, and identifiers. Rota Nacional’s barrier applies organizational policy to detected personal data before model execution, but it does not fix the WSS4J vulnerability.