CVE-2026-91864: Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion
Published Sep 18, 2026
·Updated
A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
Affected Software
1 affected component
Apache Neethi<3.2.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Neethito a version that resolves this vulnerability.Fixed in 3.2.4Patch CVE-2026-91864
Event History
Sep 21, 2026
CVE Published
via MITRE·11:26 AM
Data Sourced
via MITRE·11:26 AM
Description