Junglewise Threat Intelligence

CVE-2026-91863: Apache Neethi stack exhaustion via deeply nested WS-Policy elements

CVE-2026-91863 · Severity: high · CVSS 7.5 · Published 2026-09-21

Technologies: Apache Neethi. Vendors: Apache.

Executive brief

Apache Neethi is a library that processes WS-Policy documents used in web services. An attacker can craft a specially designed WS-Policy file with deeply nested elements that bypasses the parser's safety checks, causing the application to crash by exhausting available thread stack memory. This results in a denial of service, making services unavailable.

Technical details

The vulnerability exists in Neethi's WS-Policy parser, which fails to properly enforce its nesting-depth limit when processing maliciously crafted policy documents. An attacker can send a specially constructed WS-Policy XML document that triggers recursive parsing without hitting the depth limit, leading to stack exhaustion and parser crash. This is a network-accessible denial of service affecting applications using Neethi versions before 3.2.4.

Affected products

  • Apache Neethi before 3.2.4

Timeline

  • 2026-09-21: disclosed

References

Related threats