Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue.
Metrics
Affected Vendors & Products
References
History
Fri, 24 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 24 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue. | |
| Title | Apache Neethi: Uncontrolled recursion in policy processing | |
| Weaknesses | CWE-400 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-07-24T18:38:17.880Z
Reserved: 2026-07-24T07:16:40.533Z
Link: CVE-2026-66142
Updated: 2026-07-24T14:34:50.576Z
No data.
No data.
OpenCVE Enrichment
No data.