CVE-2026-91864 - Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion
CVE ID :CVE-2026-91864
Published : Sept. 21, 2026, 12:17 p.m. | 52 minutes ago
Description :A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 21, 2026, 12:17 p.m. | 52 minutes ago
Description :A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...