Executive brief
Apache Neethi, a library used for managing Web Services policies, is vulnerable to a denial-of-service attack. An attacker can provide a specially crafted policy that bypasses safety limits, causing the system to consume excessive resources. This can lead to application slowdowns or complete service outages, preventing legitimate users from accessing the system.
Technical details
Apache Neethi is vulnerable to uncontrolled resource consumption (CWE-400). The vulnerability exists because certain crafted policies can bypass the maximum number of normalized policy alternatives limit introduced in version 3.2.2. An attacker can exploit this by submitting a malicious policy for processing, leading to excessive CPU or memory consumption and a denial-of-service (DoS) condition. The issue is resolved in Apache Neethi version 3.2.3.
Affected products
- Apache Software Foundation Neethi versions before 3.2.3
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory
- 2026-07-24: patched: Fixed in version 3.2.3