Executive brief
Neethi is an Apache library that processes web service policy documents. When fetching a policy from a remote server, the library only enforces a timeout per individual read operation, not for the entire transfer. An attacker can exploit this by sending data very slowly, keeping the connection alive indefinitely and exhausting the application's thread pool, causing a denial of service.
Technical details
Neethi lacks a total timeout for remote policy reference fetches; it only enforces per-read timeouts. An attacker can send bytes at an extremely slow rate to keep the socket open indefinitely, tying up the calling thread and eventually exhausting available threads. This is a denial of service via thread exhaustion that requires only network-level access to a host making policy fetch requests.
Affected products
- Apache Neethi before 3.2.4
Timeline
- 2026-09-21: disclosed