Allocation of Resources Without Limits or Throttling in Apache Neethi - CVE-2026-42402
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to unbounded resource allocation in policy normalization when parsing specially crafted WS-Policy documents. A remote attacker can send a specially crafted WS-Policy document to cause a denial of service.
The issue can exhaust the JVM heap during normalization because an exponential Cartesian cross-product expansion generates an excessive number of policy alternatives.
Affected software
Red Hat Camel for Spring Boot
How to mitigate CVE-2026-42402
Red Hat Camel for Spring Boot - update to 4.14