Denial of Service Risk in Apache Software's Policy Management
CVE-2026-66144
Currently unrated
What is CVE-2026-66144?
A vulnerability exists in Apache Software's policy management tools where remote policy references, if retrieved manually via the API, can lead to a denial of service. This occurs when a large policy is fetched, overwhelming the system's resources. Users are advised to update to version 3.2.3, which mitigates the issue by setting a default maximum size limit on data read from remote policy references, thereby preventing potential service disruptions.
Affected Version(s)
Apache Neethi 0 < 3.2.3