Uncontrolled Recursion in Apache Neethi - CVE-2026-91863
Published: September 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in the Apache Neethi WS-Policy parser when parsing a crafted WS-Policy document with deeply nested policy elements. A remote attacker can supply a specially crafted WS-Policy document to exhaust the thread stack and crash the parser.