Executive brief
Apache Neethi is a library that processes WS-Policy documents used in web services. An attacker can craft a specially designed WS-Policy file with deeply nested elements that bypasses the parser's safety checks, causing the application to crash by exhausting available thread stack memory. This results in a denial of service, making services unavailable.
Technical details
The vulnerability exists in Neethi's WS-Policy parser, which fails to properly enforce its nesting-depth limit when processing maliciously crafted policy documents. An attacker can send a specially constructed WS-Policy XML document that triggers recursive parsing without hitting the depth limit, leading to stack exhaustion and parser crash. This is a network-accessible denial of service affecting applications using Neethi versions before 3.2.4.
Affected products
- Apache Neethi before 3.2.4
Timeline
- 2026-09-21: disclosed