Impact
A crafted WS-Policy document containing deeply nested policy elements can bypass Apache Neethi’s intended nesting‑depth limit and cause the parser to recurse until the thread stack is exhausted, leading to a crash. The result is a denial‑of‑service condition for the application or service processing the document. The weakness is an uncontrolled recursion that results in resource exhaustion.
Affected Systems
Apache Neethi, provided by the Apache Software Foundation, is impacted on all releases earlier than version 3.2.4. Users of Neethi that rely on it to parse WS‑Policy documents are vulnerable unless they upgrade to 3.2.4 or later.
Risk and Exploitability
Because the vulnerability only manifests when a specially crafted WS‑Policy document is parsed, the attacker must be able to submit such a document to a Neethi‑based service. The exact CVSS score is not listed, and EPSS data is currently unavailable, but the denial‑of‑service nature combined with the fact that the vulnerability is not in the CISA KEV catalog suggests that the threat surface remains high for exposed services. An attacker could repeatedly send malicious documents to exhaust resources and disrupt service availability.
OpenCVE Enrichment