Apache
Apache Neethi: vulnerabilidades y CVE
Apache Neethi tiene 11 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses11
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-91867 | Media (4.3) | 0.50% | — | 21 sept 2026 | When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial… |
| CVE-2026-91866 | Alta (7.5) | 0.74% | — | 21 sept 2026 | A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version… |
| CVE-2026-91865 | Alta (7.5) | 0.74% | — | 21 sept 2026 | A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are… |
| CVE-2026-91864 | Alta (7.5) | 0.74% | — | 21 sept 2026 | A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users… |
| CVE-2026-91863 | Alta (7.5) | 0.76% | — | 21 sept 2026 | A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service). Users are recommended to upgrade… |
| CVE-2026-66144 | Alta (7.5) | 0.74% | — | 24 jul 2026 | Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to… |
| CVE-2026-66143 | Alta (7.5) | 0.85% | — | 24 jul 2026 | It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource… |
| CVE-2026-66142 | Alta (7.5) | 0.74% | — | 24 jul 2026 | Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory… |
| CVE-2026-42404 | Alta (7.2) | 0.58% | — | 1 may 2026 | Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote… |
| CVE-2026-42403 | Alta (7.5) | 0.80% | — | 1 may 2026 | Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (where Policy A references Policy B which references Policy A), the policy… |
| CVE-2026-42402 | Alta (7.5) | 0.74% | — | 1 may 2026 | Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-product expansion during… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.