CVE-2026-42404: Apache Neethi: Unrestricted HTTP Redirect Following in Policy References

Published May 1, 2026
·
Updated

Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden.

Users are recommended to upgrade to version 3.2.2, which fixes this issue.

Affected Software

4 affected components
Apache Neethi<3.2.2
Apache Neethi<3.2.2
IBM Cognos Analytics<=12.1.0 - 12.1.3 FP1
IBM Cognos Analytics<=12.0.4 - 12.0.4 FP2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache Neethi to a version that resolves this vulnerability.

    Fixed in 3.2.2
  2. Configuration

    Configure/ensure Apache Neethi applies the restriction introduced in v3.2.2: allow only http or https URIs when resolving remote policy references via the PolicyReference API, and forbid link-local/multicast/any-local addresses.

    Apache Neethi PolicyReference API allowed_policy_reference_uris = http, https only (forbid link-local/multicast/any-local addresses)

Event History

May 1, 2026
CVE Published
via MITRE·09:46 AM
Data Sourced
via MITRE·09:46 AM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·11:01 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeaknessAffected Software
Sep 11, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2026-42404?

CVE-2026-42404 is classified as a moderate severity vulnerability due to unrestricted HTTP redirect following in policy references.

2

How do I fix CVE-2026-42404?

To mitigate CVE-2026-42404, update Apache Neethi to version 3.2.2 or later, where this issue is addressed.

3

What systems are affected by CVE-2026-42404?

CVE-2026-42404 affects Apache Neethi versions up to 3.2.2 that utilize the PolicyReference API for fetching remote policy references.

4

What are the risks associated with CVE-2026-42404?

The risks associated with CVE-2026-42404 include exposure to external malicious URLs, leading to potential redirection attacks.

5

How can I identify if my application is vulnerable to CVE-2026-42404?

To identify vulnerability to CVE-2026-42404, check if your application uses Apache Neethi versions prior to 3.2.2 and employs the PolicyReference API.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203