A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service).
Users are recommended to upgrade to version 3.2.4, which fixes this issue.
Users are recommended to upgrade to version 3.2.4, which fixes this issue.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 21 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue. | |
| Title | Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-09-21T11:26:20.054Z
Reserved: 2026-09-15T09:54:19.238Z
Link: CVE-2026-91864
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.