Threat intelligence dashboard
CVE-2026-91865high

Apache Neethi: Crafted policy references cause exponential expansion during normalization leading to denial of service

A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.

Risk score

7.5

CVSS 3.1

Vendor
Apache Software Foundation
Product
Apache Neethi
CWE
CWE-770
Published
Sep 21, 2026
Updated
Sep 21, 2026
CISA KEV
Not flagged

Affected products and versions

Apache Neethi

Apache Software Foundation

Version / rangeStatusType
0 to before 3.2.4affectedsemver

Technical metrics

7.5

CVSS 3.1

Severity
high
Source
CISA-ADP
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H