Apache Neethi

5 known vulnerabilities in Apache Neethi, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-91867 CVSS 4.3 medium When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes…
  • CVE-2026-91866 CVSS 7.5 high A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU…
  • CVE-2026-91865 CVSS 7.5 high A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during…
  • CVE-2026-91864 CVSS 7.5 high A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without…
  • CVE-2026-91863 CVSS 7.5 high A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread…