GHSA-gg9r-wr4p-w63h
HIGHCVE-2026-40994Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules, weakening protocol-level checks.
- Affected
- >= 5.0.0, <= 5.0.1
- Fixed in
- 5.0.2
- Weakness
- CWE-1188
- Published
- 2026-06-11
- Source
- github