Denial of Service Vulnerability in Neethi's Policy Processing
CVE-2026-91866

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
21 September 2026

What is CVE-2026-91866?

A vulnerability exists in Apache Neethi due to the handling of specially crafted WS-Policy documents, which can lead to excessive CPU usage and potential denial of service. The exploitation of this vulnerability may cause the policy intersection process to enter an exponential workload, leading to significant system resource consumption and unavailability. It is highly recommended for users to upgrade to Neethi version 3.2.4 or later to mitigate this issue.

Affected Version(s)

Apache Neethi 0 < 3.2.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was found using Claude agents to study the security of open-source projects
.