CVE-2026-91867
- EPSS 0.22%
- Veröffentlicht 21.09.2026 11:27:45
- Zuletzt bearbeitet 25.09.2026 13:09:43
When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service). Users are recomme...
CVE-2026-91866
- EPSS 0.42%
- Veröffentlicht 21.09.2026 11:27:15
- Zuletzt bearbeitet 25.09.2026 13:09:24
A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
CVE-2026-91865
- EPSS 0.51%
- Veröffentlicht 21.09.2026 11:26:52
- Zuletzt bearbeitet 25.09.2026 13:09:32
A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgrade to versio...
CVE-2026-91864
- EPSS 0.51%
- Veröffentlicht 21.09.2026 11:26:20
- Zuletzt bearbeitet 25.09.2026 13:09:39
A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to upgrade to ver...
CVE-2026-91863
- EPSS 0.53%
- Veröffentlicht 21.09.2026 11:25:26
- Zuletzt bearbeitet 24.09.2026 20:34:14
A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes th...
CVE-2026-66144
- EPSS 0.48%
- Veröffentlicht 24.07.2026 12:08:27
- Zuletzt bearbeitet 27.07.2026 14:32:06
Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, whic...
CVE-2026-66143
- EPSS 0.51%
- Veröffentlicht 24.07.2026 12:07:52
- Zuletzt bearbeitet 27.07.2026 14:35:07
It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upg...
CVE-2026-66142
- EPSS 0.48%
- Veröffentlicht 24.07.2026 12:07:26
- Zuletzt bearbeitet 27.07.2026 14:35:32
Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommen...
CVE-2026-42404
- EPSS 0.5%
- Veröffentlicht 01.05.2026 09:46:49
- Zuletzt bearbeitet 01.05.2026 18:06:24
Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made f...
CVE-2026-42402
- EPSS 0.71%
- Veröffentlicht 01.05.2026 08:54:41
- Zuletzt bearbeitet 01.05.2026 18:08:59
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-product expansion during the normalization process, cau...