Input validation error in Apache Neethi - CVE-2026-42403
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the policy normalization process when parsing WS-Policy documents containing circular policy references. A remote attacker can supply a specially crafted policy document to cause a denial of service.
The issue can result in an infinite loop, excessive recursion, a stack overflow, or an application hang.
Affected software
Red Hat Camel for Spring Boot
How to mitigate CVE-2026-42403
Red Hat Camel for Spring Boot - update to 4.14