Apache

Neethi

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 21.09.2026 11:27:45
  • Zuletzt bearbeitet 25.09.2026 13:09:43

When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service). Users are recomme...

  • EPSS 0.42%
  • Veröffentlicht 21.09.2026 11:27:15
  • Zuletzt bearbeitet 25.09.2026 13:09:24

A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.

  • EPSS 0.51%
  • Veröffentlicht 21.09.2026 11:26:52
  • Zuletzt bearbeitet 25.09.2026 13:09:32

A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgrade to versio...

  • EPSS 0.51%
  • Veröffentlicht 21.09.2026 11:26:20
  • Zuletzt bearbeitet 25.09.2026 13:09:39

A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to upgrade to ver...

  • EPSS 0.53%
  • Veröffentlicht 21.09.2026 11:25:26
  • Zuletzt bearbeitet 24.09.2026 20:34:14

A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes th...

  • EPSS 0.48%
  • Veröffentlicht 24.07.2026 12:08:27
  • Zuletzt bearbeitet 27.07.2026 14:32:06

Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, whic...

  • EPSS 0.51%
  • Veröffentlicht 24.07.2026 12:07:52
  • Zuletzt bearbeitet 27.07.2026 14:35:07

It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upg...

  • EPSS 0.48%
  • Veröffentlicht 24.07.2026 12:07:26
  • Zuletzt bearbeitet 27.07.2026 14:35:32

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommen...

  • EPSS 0.5%
  • Veröffentlicht 01.05.2026 09:46:49
  • Zuletzt bearbeitet 01.05.2026 18:06:24

Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made f...

  • EPSS 0.71%
  • Veröffentlicht 01.05.2026 08:54:41
  • Zuletzt bearbeitet 01.05.2026 18:08:59

Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-product expansion during the normalization process, cau...