CVE-2026-66142 PUBLISHED

Apache Neethi: Uncontrolled recursion in policy processing

Assigner: apache
Reserved: 24.07.2026 Published: 24.07.2026 Updated: 24.07.2026

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue.

Product Status

Vendor Apache Software Foundation
Product Apache Neethi
Versions Default: unaffected
  • affected from 0 to 3.2.3 (excl.)

Credits

  • Reported by LTSHFWJT finder

References

Problem Types

  • CWE-400 Uncontrolled Resource Consumption CWE