CVE-2026-91867 - Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely
CVE ID :CVE-2026-91867
Published : Sept. 21, 2026, 12:17 p.m. | 52 minutes ago
Description :When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 21, 2026, 12:17 p.m. | 52 minutes ago
Description :When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...