CVE-2026-87830
EUVD-2026-8979230.09.2026, 12:17
In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| apache | wss4j | 4.0.0 ≤ 𝑥 < 4.0.2 | CNA |
| apache | wss4j | 3.0.0 ≤ 𝑥 < 3.0.6 | CNA |
| apache | wss4j | 𝑥 < 2.4.4 | CNA |
Debian Releases