← voltar
CVE-2026-91867mediumCWE-400

Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely

13Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 4.3epss 0.5%
probabilidade de exploração
0.5%top 60% das CVEs
exploração observada
nãonenhuma fonte reporta
When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L