Junglewise Threat Intelligence

CVE-2026-66143: Apache Neethi denial of service via policy normalization bypass

CVE-2026-66143 · Severity: info · CVSS 0 · Published 2026-07-24

Technologies: Apache Software Foundation Neethi. Vendors: Apache Software Foundation.

Executive brief

Apache Neethi, a library used for managing Web Services policies, is vulnerable to a denial-of-service attack. An attacker can provide a specially crafted policy that bypasses safety limits, causing the system to consume excessive resources. This can lead to application slowdowns or complete service outages, preventing legitimate users from accessing the system.

Technical details

Apache Neethi is vulnerable to uncontrolled resource consumption (CWE-400). The vulnerability exists because certain crafted policies can bypass the maximum number of normalized policy alternatives limit introduced in version 3.2.2. An attacker can exploit this by submitting a malicious policy for processing, leading to excessive CPU or memory consumption and a denial-of-service (DoS) condition. The issue is resolved in Apache Neethi version 3.2.3.

Affected products

  • Apache Software Foundation Neethi versions before 3.2.3

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory
  • 2026-07-24: patched: Fixed in version 3.2.3

References

Related threats