Resource exhaustion in Apache Neethi - CVE-2026-91865
Published: September 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in Apache Neethi policy normalization when processing a crafted WS-Policy document containing repeated policy references. A remote attacker can supply a crafted WS-Policy document to cause a denial of service.