Denial of Service Vulnerability in Neethi from Apache Software Foundation
CVE-2026-91867

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
21 September 2026

What is CVE-2026-91867?

The Neethi component from Apache Software Foundation has a vulnerability that allows a malicious entity to exploit remote policy references. When Neethi fetches these references, it only limits the read time, not the overall transfer, enabling attackers to send data at a slow pace. This could cause the fetch process to remain active indefinitely, ultimately tying up system resources and resulting in a denial of service. Users are encouraged to upgrade to version 3.2.4 to mitigate this risk and protect their applications.

Affected Version(s)

Apache Neethi 0 < 3.2.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was found using Claude agents to study the security of open-source projects
.