PT-2026-36310 · Apache · Apache Neethi

Colm O Heigeartaigh

·

Published

2026-05-01

·

Updated

2026-05-02

·

CVE-2026-42403

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Neethi versions prior to 3.2.2
Description Apache Neethi fails to properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (for example, Policy A references Policy B, which in turn references Policy A), the policy normalization process may enter an infinite loop or cause excessive recursion. This can result in a stack overflow or an application hang, allowing an attacker to cause a Denial of Service condition by crafting malicious policy documents.
Recommendations Upgrade to version 3.2.2.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2026-42403
GHSA-2HFH-9H53-QC24

Affected Products

Apache Neethi