Intel

AIKIDO-2026-10687

neethi is vulnerable to Uncontrolled Resource Consumption

Uncontrolled Resource ConsumptionCVE-2026-42402

75

High Risk

This Affects:

JAVAneethi
0.0.1 - 3.2.1
Fixed in 3.2.2
Are you affected? Scan for Free

TL;DR

Algorithmic complexity in policy normalization in Apache Neethi allows specially crafted WS-Policy documents to trigger an exponential Cartesian cross-product expansion, resulting in unbounded memory allocation. This can exhaust the JVM heap and cause application crashes, leading to a denial of service (dos) vulnerability. Version 3.2.2 introduces limits on the number of normalized policy alternatives to prevent uncontrolled resource consumption.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

neethi is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 3.2.1.

How to fix this

Upgrade the org.apache.neethi:neethi library to the patch version.