4.3
CVE-2026-91867
- EPSS 0.22%
- Veröffentlicht 21.09.2026 11:27:45
- Zuletzt bearbeitet 25.09.2026 13:09:43
- Erkennungen
Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely
When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.127 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
https://lists.apache.org/thread/dsr2ktf199mqhw2jtlbklyz7tzd86ycd
http://www.openwall.com/lists/oss-security/2026/09/18/14