Executive brief
Apache Neethi is a library that processes WS-Policy documents used in web services. A specially crafted policy document with repeated references can cause Neethi to exponentially re-expand the same references during normalization, consuming enormous amounts of CPU and memory and rendering systems unresponsive.
Technical details
The vulnerability is a denial-of-service issue in the WS-Policy normalization process where repeated policy references trigger exponential re-expansion, leading to CPU and memory exhaustion. The attack requires network access to send a malicious policy document to an application using vulnerable Neethi versions. Apache has released version 3.2.4 as a fix.
Affected products
- Apache Neethi prior to 3.2.4
Timeline
- 2026-09-21: disclosed