Spring Web Services: WSS4J validation does not use configured replay cache
Low severity
GitHub Reviewed
Published
Jun 11, 2026
to the GitHub Advisory Database
•
Updated Aug 21, 2026
Package
Affected versions
>= 5.0.0, <= 5.0.1
>= 4.1.0, <= 4.1.3
>= 4.0.0, <= 4.0.18
>= 3.1.0, <= 3.1.8
Patched versions
5.0.2
4.1.4
Description
Published by the National Vulnerability Database
Jun 11, 2026
Published to the GitHub Advisory Database
Jun 11, 2026
Reviewed
Aug 21, 2026
Last updated
Aug 21, 2026
Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when operators configured a replay cache on the interceptor.
Affected versions:
Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
References