Junglewise Threat Intelligence

CVE-2026-91865: Apache Neethi exponential policy expansion denial of service

CVE-2026-91865 · Severity: high · CVSS 7.5 · Published 2026-09-21

Technologies: Apache Neethi. Vendors: Apache.

Executive brief

Apache Neethi is a library that processes WS-Policy documents used in web services. A specially crafted policy document with repeated references can cause Neethi to exponentially re-expand the same references during normalization, consuming enormous amounts of CPU and memory and rendering systems unresponsive.

Technical details

The vulnerability is a denial-of-service issue in the WS-Policy normalization process where repeated policy references trigger exponential re-expansion, leading to CPU and memory exhaustion. The attack requires network access to send a malicious policy document to an application using vulnerable Neethi versions. Apache has released version 3.2.4 as a fix.

Affected products

  • Apache Neethi prior to 3.2.4

Timeline

  • 2026-09-21: disclosed

References

Related threats