CVE-2026-91866
A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
- Published Sep 21, 2026
- CVSS 7.5 high
- 0.7% chance of exploitation in the next 30 days (EPSS)
- A fix is available