CVE-2026-85532
🟡 Monitoruj
Błąd w Apache WSS4J pozwala na wykorzystanie słabych kluczy i nadmierne zużycie zasobów.
CVSS
7.5
EPSS
0.5%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)
Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages. The fixes enforce a minimum key length of 16 bytes, a maximum length of 512 bytes, and a maximum offset of 4096 bytes. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.5% |
| Opublikowano (NVD) | 2026-09-30 12:17:13 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 20:14:49 UTC |
Referencje
- https://lists.apache.org/thread.html/7jllcpbf4nbzhdp2vchz5yplnl5w6vd6 ([email protected]) [Mailing List, Vendor Advisory]
- http://www.openwall.com/lists/oss-security/2026/09/30/8 (af854a3a-2127-422b-91ae-364da2661108) [Mailing List, Third Party Advisory]