Junglewise Threat Intelligence

CVE-2026-91866: Apache Neethi policy intersection exponential complexity denial of service

CVE-2026-91866 · Severity: high · CVSS 7.5 · Published 2026-09-21

Technologies: Apache Neethi. Vendors: Apache.

Executive brief

Apache Neethi is a library that processes WS-Policy documents used in web services. A malicious pair of specially crafted policy documents can cause the policy intersection algorithm to consume exponential CPU resources, resulting in severe service degradation or complete denial of service to applications using the library.

Technical details

The vulnerability exists in Neethi's policy-intersection algorithm, which can be forced into exponential-time behavior when processing specially crafted WS-Policy documents. An unauthenticated attacker with network access can send malicious policy documents to trigger this condition, causing CPU exhaustion. The issue is resolved in version 3.2.4.

Affected products

  • Apache Neethi before 3.2.4

Timeline

  • 2026-09-21: disclosed

References

Related threats