CVE-2026-66143 PUBLISHED

Apache Neethi: Missing global alternative-output budget across policy computation paths

Assigner: apache
Reserved: 24.07.2026 Published: 24.07.2026 Updated: 24.07.2026

It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue.

Product Status

Vendor Apache Software Foundation
Product Apache Neethi
Versions Default: unaffected
  • affected from 0 to 3.2.3 (excl.)

Credits

  • Reported by LTSHFWJT finder

References

Problem Types

  • CWE-400 Uncontrolled Resource Consumption CWE