CVE-2026-41000 Details
Description
Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when operators configured a replay cache on the interceptor. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
A vulnerability exists in Spring Web Services versions 5.0.0 through 5.0.1, 4.1.0 through 4.1.3, 4.0.0 through 4.0.18, and 3.1.0 through 3.1.8. The issue arises because the Wss4jSecurityInterceptor does not consistently integrate Apache WSS4J ReplayCache instances into RequestData for validation checks. This inconsistency can undermine protections against the replay of UsernameToken nonces, creation timestamps, Timestamp elements, and certain SAML one-time-use semantics. Consequently, attackers could exploit this vulnerability by resubmitting still-valid cryptographic material within the acceptance window, even when a replay cache is configured on the interceptor.
Users of affected versions should upgrade to the fixed version. For Spring Web Services 5.0.x, upgrade to 5.0.2 or 5.0.1.1 (Enterprise Support Only). For 4.1.x, upgrade to 4.1.4 or 4.1.3.1 (Enterprise Support Only). For 4.0.x, upgrade to 4.0.19 (Enterprise Support Only). For 3.1.x, upgrade to 3.1.9 (Enterprise Support Only). If an upgrade is not possible, extend Wss4jSecurityInterceptor and override the initializeValidationRequestData method to manually set up the ReplayCache.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://spring.io/security/cve-2026-41000 | [email protected] | Vendor AdvisoryMitigation |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-294 | Authentication Bypass by Capture-replay | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| broadcom spring web services | < 3.1.9 >= 4.0.0, < 4.0.19 >= 4.1.0, < 4.1.3.1 >= 5.0.0, < 5.0.1.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | Initial Analysis | [email protected] |
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 23, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 11, 2026 | New CVE Received | [email protected] |