Posted by Colm O hEigeartaigh on Sep 30 Severity: moderate Affected versions: - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-stax) 4.0.0 before 4.0.2 - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-stax) 3.0.0 before 3.0.6 - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-stax) before 2.4.4 Description: In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set....
CVE-2026-92121: Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an STR-Transform reference
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q3/1025
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.





