Denial of Service Vulnerability in Apache Neethi WS-Policy Parser
CVE-2026-91863

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
21 September 2026

What is CVE-2026-91863?

A vulnerability exists in Apache Neethi’s WS-Policy parser, where a specially crafted WS-Policy document containing deeply nested policy elements can surpass the parser's configured nesting-depth limit. This condition can lead to excessive use of the thread stack, ultimately resulting in a denial of service. Users of versions prior to 3.2.4 are advised to upgrade to resolve this issue and enhance the security of their applications.

Affected Version(s)

Apache Neethi 0 < 3.2.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was found using Claude agents to study the security of open-source projects
.