Description
Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, which fixes this issue by imposing a default maximum size on data read from remote policy references.
Published: 2026-07-24
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Apache Neethi allows an attacker to manually trigger the retrieval of a remote policy reference via the API. Based on the description, it is inferred that when a very large policy is fetched, the library consumes excessive resources during the download, which can exhaust server memory or CPU and cause a denial of service. The weakness is a resource exhaustion vulnerability.

Affected Systems

The issue affects Apache Neethi, a subproject of the Apache Software Foundation. Users using versions prior to 3.2.3 are vulnerable. The vendor recommends upgrading to version 3.2.3, which introduces a default maximum size for data read from remote policy references.

Risk and Exploitability

The CVSS score is 7.5, indicating a high severity. The EPSS score is less than 1%, implying that the probability of exploitation is low but not negligible. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires the ability to invoke the API that fetches remote policy references, which is likely performed remotely by an attacker with network access to the API endpoint.

Generated by OpenCVE AI on August 4, 2026 at 15:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Neethi to version 3.2.3 or later to enforce a maximum download size
  • Disable or restrict the API that allows manual retrieval of remote policy references to trusted users only
  • Monitor server logs for unusually large policy fetches and implement rate limiting or request filtering if such attempts are detected

Generated by OpenCVE AI on August 4, 2026 at 15:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache neethi
Vendors & Products Apache
Apache neethi

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, which fixes this issue by imposing a default maximum size on data read from remote policy references.
Title Apache Neethi: Remote PolicyReference fetch lacks resource bounds
Weaknesses CWE-400
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-24T18:42:19.733Z

Reserved: 2026-07-24T07:32:05.484Z

Link: CVE-2026-66144

cve-icon Vulnrichment

Updated: 2026-07-24T14:34:52.723Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-24T13:18:29.467

Modified: 2026-07-27T14:32:06.660

Link: CVE-2026-66144

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:15:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption