← voltar
CVE-2026-91864highCWE-770

Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion

21Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 7.5epss 0.5%
probabilidade de exploração
0.5%top 57% das CVEs
exploração observada
nãonenhuma fonte reporta
A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H