Junglewise Threat Intelligence

CVE-2026-91867: Neethi remote policy fetch thread exhaustion

CVE-2026-91867 · Severity: medium · CVSS 4.3 · Published 2026-09-21

Technologies: Apache Neethi. Vendors: Apache.

Executive brief

Neethi is an Apache library that processes web service policy documents. When fetching a policy from a remote server, the library only enforces a timeout per individual read operation, not for the entire transfer. An attacker can exploit this by sending data very slowly, keeping the connection alive indefinitely and exhausting the application's thread pool, causing a denial of service.

Technical details

Neethi lacks a total timeout for remote policy reference fetches; it only enforces per-read timeouts. An attacker can send bytes at an extremely slow rate to keep the socket open indefinitely, tying up the calling thread and eventually exhausting available threads. This is a denial of service via thread exhaustion that requires only network-level access to a host making policy fetch requests.

Affected products

  • Apache Neethi before 3.2.4

Timeline

  • 2026-09-21: disclosed

References

Related threats