Description
It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue.
Published: 2026-07-24
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Apache Neethi contains a flaw that permits an attacker to supply specially crafted policies which bypass the global alternative-output budgeting that protects against excessive policy alternatives. When the budget check is circumvented, the policy engine attempts to generate a large number of normalized policy alternatives, consuming significant CPU and memory. The result is a denial of service that can degrade application availability and overall system performance.

Affected Systems

All installations of Apache Neethi running version 3.2.2 or earlier are affected. The issue was resolved in the 3.2.3 release, which reinstates the budgeting safeguard.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity impact. The EPSS score of less than 1% suggests a very low probability of observed exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves supplying crafted policies, implying that an attacker must have the ability to influence policy definitions. If an application accepts dynamic policy input from untrusted sources, the risk increases, but without such access the exploitation path is limited.

Generated by OpenCVE AI on August 3, 2026 at 20:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Neethi to version 3.2.3 or later.
  • Restrict permissions so that only trusted administrators can supply or modify policy files.
  • Implement resource monitoring or limits on the policy engine to detect and mitigate abnormal consumption patterns.

Generated by OpenCVE AI on August 3, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache neethi
Vendors & Products Apache
Apache neethi

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue.
Title Apache Neethi: Missing global alternative-output budget across policy computation paths
Weaknesses CWE-400
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-24T18:40:12.434Z

Reserved: 2026-07-24T07:26:50.294Z

Link: CVE-2026-66143

cve-icon Vulnrichment

Updated: 2026-07-24T14:34:51.649Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-24T13:18:29.350

Modified: 2026-07-27T14:35:07.563

Link: CVE-2026-66143

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:30:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption