← volver
CVE-2026-91867mediumCWE-400

Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely

13Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 4.3epss 0.5%
probabilidad de explotación
0.5%top 60% de las CVE
explotación observada
noninguna fuente lo reporta
When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L