Inefficient Algorithmic Complexity in Apache Neethi - CVE-2026-91866
Published: September 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in Neethi's policy-intersection when processing a specially crafted pair of WS-Policy documents. A remote attacker can provide a specially crafted pair of WS-Policy documents to cause a denial of service.