Description
A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service).
Users are recommended to upgrade to version 3.2.4, which fixes this issue.
Published: 2026-09-21
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability arises when a specially crafted WS-Policy document includes an assertion with unlimited content. Neethi copies this content into heap memory without enforcing its size limits, causing the process to exhaust available memory. The result is a denial‑of‑service condition that can bring affected applications or services down. This flaw is a maximum memory consumption weakness (CWE‑770).

Affected Systems

Apache Neethi, versions prior to 3.2.4 are susceptible; upgrading to 3.2.4 eliminates the issue.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. However, the memory exhaustion attack path is straightforward for an attacker who can supply a crafted WS-Policy to a Neethi‑powered endpoint. The impact is a complete denial of service for the target application. Due to the lack of mitigation controls in unpatched versions, the risk remains high.

Generated by OpenCVE AI on September 21, 2026 at 12:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Neethi to version 3.2.4 or later.
  • Restart any services that use Neethi after applying the update.
  • Restrict inbound policy documents to trusted clients and consider disabling WS‑Policy processing for external interfaces if not required.

Generated by OpenCVE AI on September 21, 2026 at 12:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
References

Mon, 21 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770

Mon, 21 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache neethi
Vendors & Products Apache
Apache neethi

Mon, 21 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
Title Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-21T13:27:39.838Z

Reserved: 2026-09-15T09:54:19.238Z

Link: CVE-2026-91864

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-21T12:17:24.807

Modified: 2026-09-21T13:17:11.557

Link: CVE-2026-91864

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T13:00:14Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling