Vulnerabilities
Vulnerable Software
Apache:  >> Neethi  >> 3.2.2  Security Vulnerabilities
Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue.
CVSS Score
7.5
EPSS Score
0.005
Published
2026-07-24
It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue.
CVSS Score
7.5
EPSS Score
0.005
Published
2026-07-24
Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, which fixes this issue by imposing a default maximum size on data read from remote policy references.
CVSS Score
7.5
EPSS Score
0.005
Published
2026-07-24


Contact Us

Shodan ® - All rights reserved