Executive brief
Apache Neethi is a library that processes WS-Policy documents used in web services. A malicious pair of specially crafted policy documents can cause the policy intersection algorithm to consume exponential CPU resources, resulting in severe service degradation or complete denial of service to applications using the library.
Technical details
The vulnerability exists in Neethi's policy-intersection algorithm, which can be forced into exponential-time behavior when processing specially crafted WS-Policy documents. An unauthenticated attacker with network access can send malicious policy documents to trigger this condition, causing CPU exhaustion. The issue is resolved in version 3.2.4.
Affected products
- Apache Neethi before 3.2.4
Timeline
- 2026-09-21: disclosed