CVE-2026-92121 Apache WSS4J 签名策略绕过漏洞
影响攻击者可绕过签名校验实施 XML 签名包装攻击
Apache WSS4J 的流式(StAX)代码在处理使用 WS-Security STR-Transform 的签名引用时,会永久置位内部“位于已签名内容中”的标志。WS-SecurityPolicy 执行器依据该标志判断元素是否需要校验,导致后续消息不再评估 SignedParts 和 SignedElements。
影响范围
受影响的是 WSS4J 的流式(StAX)处理代码,DOM 代码不受影响。官方修复版本为 4.0.2、3.0.6、2.4.4,具体受影响版本范围暂无公开信息。
漏洞详情
该漏洞属于安全策略绕过(可导致 XML 签名包装攻击)。成因是 STR-Transform 签名引用处理时内部状态标志未正确复位,使策略执行器误认为后续元素已处于签名保护范围内。攻击者可借此构造消息,使要求 SOAP Body 签名的策略在 Body 实际未签名时仍被判定满足,从而绕过签名校验。签名验证本身不受影响。
利用条件与风险
利用前提是目标使用 WSS4J 流式(StAX)处理并启用 WS-SecurityPolicy 校验。实战中可绕过 SOAP Body 签名要求,为 XML 签名包装攻击创造条件,风险较高。
修复建议
官方建议升级至 4.0.2、3.0.6 或 2.4.4 版本修复该问题。临时缓解措施暂无公开信息。
In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal “inside signed content” flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, so it stops evaluating SignedParts and SignedElements for the rest of the message. A policy requiring the SOAP Body to be signed is then satisfied even when the Body carries no signature, removing the protection against XML Signature Wrapping. Signature verification itself is unaffected. The DOM code is not affected.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4 which fix this issue.