CVE-2026-41000

Updated on 11 Jun 2026

Severity

3.7 Low severity

Details

CVSS score
3.7
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Overview

About vulnerability

Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when operators configured a replay cache on the interceptor, allowing attackers to re-submit still-valid cryptographic material within the acceptance window.

Preconditions include validation of constructs that rely on replay detection, a service that accepts repeated SOAP messages over the network, and configurations that expect WSS4J replay caches to be enforced.

Details

Affected product:
Spring , camel
Affected packages:
Spring Boot @ 2.7.18 (+2581 more)