Resource exhaustion in Apache Neethi - CVE-2026-91867
Published: September 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a missing total transfer timeout in remote policy reference fetching when fetching a remote policy reference from a server that slowly trickles bytes. A remote attacker can slowly transmit a remote policy reference to cause a denial of service.