Denial of Service Vulnerability in Apache Neethi Software
CVE-2026-91864

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
21 September 2026

What is CVE-2026-91864?

A crafted WS-Policy document can be utilized to pack an excessive amount of content within a policy assertion, leading Neethi to copy this data into memory without adhering to size constraints. This behavior can result in a denial of service by exhausting the available heap memory. Users should ensure they upgrade to version 3.2.4 to resolve this issue effectively.

Affected Version(s)

Apache Neethi 0 < 3.2.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was found using Claude agents to study the security of open-source projects
.