CVE-2026-41000

Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when operators configured a replay cache on the interceptor. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
Configurations

No configuration.

History

23 Jul 2026, 09:10

Type Values Removed Values Added
Summary
  • (es) Wss4jSecurityInterceptor no cableaba consistentemente instancias de Apache WSS4J ReplayCache en RequestData para comprobaciones en tiempo de validación. Como resultado, las protecciones contra la repetición de nonces de UsernameToken y marcas de tiempo de creación, elementos Timestamp, y ciertas semánticas de un solo uso de SAML podrían ser ineficaces incluso cuando los operadores configuraban una caché de repetición en el interceptor. Versiones afectadas: Spring Web Services 5.0.0 hasta 5.0.1; 4.1.0 hasta 4.1.3; 4.0.0 hasta 4.0.18; 3.1.0 hasta 3.1.8.

11 Jun 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-11 07:16

Updated : 2026-07-23 09:10


NVD link : CVE-2026-41000

Mitre link : CVE-2026-41000

CVE.ORG link : CVE-2026-41000


JSON object : View

Products Affected

No product.

CWE
CWE-294

Authentication Bypass by Capture-replay