Intel

AIKIDO-2026-10686

neethi is vulnerable to Uncontrolled Resource Consumption

Uncontrolled Resource ConsumptionCVE-2026-42403 Published May 4, 2026

75

High Risk

This Affects:

JAVAneethi
0.0.1 - 3.2.1
Fixed in 3.2.2
Are you affected? Scan for Free

TL;DR

Improper detection of circular policy references in Apache Neethi allows malicious WS-Policy documents to trigger infinite loops or excessive recursion during policy normalization. This can lead to a stack overflow or application hang, resulting in a denial of service (DoS) vulnerability. Version 3.2.2 introduces proper handling of circular references to prevent uncontrolled recursion.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

neethi is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 3.2.1.

How to fix this

Upgrade the org.apache.neethi:neethi library to the patch version.