Description
A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service).
Users are recommended to upgrade to version 3.2.4, which fixes this issue.
Published: 2026-09-21
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Upgrade
AI Analysis

Impact

A crafted WS-Policy document containing deeply nested policy elements can bypass Apache Neethi’s intended nesting‑depth limit and cause the parser to recurse until the thread stack is exhausted, leading to a crash. The result is a denial‑of‑service condition for the application or service processing the document. The weakness is an uncontrolled recursion that results in resource exhaustion.

Affected Systems

Apache Neethi, provided by the Apache Software Foundation, is impacted on all releases earlier than version 3.2.4. Users of Neethi that rely on it to parse WS‑Policy documents are vulnerable unless they upgrade to 3.2.4 or later.

Risk and Exploitability

Because the vulnerability only manifests when a specially crafted WS‑Policy document is parsed, the attacker must be able to submit such a document to a Neethi‑based service. The exact CVSS score is not listed, and EPSS data is currently unavailable, but the denial‑of‑service nature combined with the fact that the vulnerability is not in the CISA KEV catalog suggests that the threat surface remains high for exposed services. An attacker could repeatedly send malicious documents to exhaust resources and disrupt service availability.

Generated by OpenCVE AI on September 21, 2026 at 12:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑provided update to Apache Neethi version 3.2.4 or later.
  • Configure the service to reject or rate‑limit exceptionally deep WS‑Policy payloads before they reach the parser, thereby preventing stack exhaustion.
  • Monitor application logs and system metrics for stack overflows or frequent parsing failures, and investigate any sudden drops in service availability.

Generated by OpenCVE AI on September 21, 2026 at 12:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
References

Mon, 21 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache neethi
Vendors & Products Apache
Apache neethi

Mon, 21 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
CWE-973

Mon, 21 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
Title Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of service
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-21T13:36:42.505Z

Reserved: 2026-09-15T09:50:54.325Z

Link: CVE-2026-91863

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-21T12:17:24.697

Modified: 2026-09-21T13:17:11.457

Link: CVE-2026-91863

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T13:00:13Z

Weaknesses