CVE-2026-66143: Apache Neethi: Missing global alternative-output budget across policy computation paths
It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Neethito a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66143?
The severity of CVE-2026-66143 is rated high with a CVSS score of 7.5.
How do I fix CVE-2026-66143?
To fix CVE-2026-66143, upgrade Apache Neethi to version 3.2.3.
What is the risk associated with CVE-2026-66143?
CVE-2026-66143 has a risk rating of 46 and can lead to denial of service attacks.
What version of Apache Neethi is affected by CVE-2026-66143?
Apache Neethi version 3.2.2 is affected by CVE-2026-66143.
What type of attack does CVE-2026-66143 potentially enable?
CVE-2026-66143 potentially enables denial of service attacks through resource consumption.