7.5
CVE-2026-66143
- EPSS 0.51%
- Veröffentlicht 24.07.2026 12:07:52
- Zuletzt bearbeitet 27.07.2026 14:35:07
- Erkennungen
Apache Neethi: Missing global alternative-output budget across policy computation paths
It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.51% | 0.407 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
https://lists.apache.org/thread/s6o6p5pvcbcsk54dlg6j699t5gxol28w
http://www.openwall.com/lists/oss-security/2026/07/24/9