CVE-2026-66142: Apache Neethi: Uncontrolled recursion in policy processing
Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Neethito a version that resolves this vulnerability.Fixed in 3.2.3Patch CVE-2026-66142
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66142?
CVE-2026-66142 has a severity rating of high, with a CVSS score of 7.5.
How do I fix CVE-2026-66142?
To fix CVE-2026-66142, upgrade to Apache Neethi version 3.2.3 or later.
What kind of attack can CVE-2026-66142 lead to?
CVE-2026-66142 may lead to a denial of service attack due to runtime memory exhaustion.
What is the cause of the vulnerability in CVE-2026-66142?
The vulnerability in CVE-2026-66142 is caused by uncontrolled recursion when parsing policies that lack policy IDs or have deeply nested structures.
When was CVE-2026-66142 published?
CVE-2026-66142 was published on July 24, 2026.