Denial of Service Vulnerability in Neethi's Policy Processing
CVE-2026-91866
Currently unrated
What is CVE-2026-91866?
A vulnerability exists in Apache Neethi due to the handling of specially crafted WS-Policy documents, which can lead to excessive CPU usage and potential denial of service. The exploitation of this vulnerability may cause the policy intersection process to enter an exponential workload, leading to significant system resource consumption and unavailability. It is highly recommended for users to upgrade to Neethi version 3.2.4 or later to mitigate this issue.
Affected Version(s)
Apache Neethi 0 < 3.2.4