CVE-2026-91865
A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
- Published Sep 21, 2026
- CVSS 7.5 high
- 0.7% chance of exploitation in the next 30 days (EPSS)
- A fix is available