Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-product expansion during the normalization process, causing unbounded memory allocation that exhausts the JVM heap. This occurs when the normalization process generates an excessive number of policy alternatives without bounds, leading to runtime memory exhaustion.
Users should upgrade to 3.2.2 which limits the maximum number of normalized policy alternatives.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/p826j0phhmr9f83wzpmys1y0bdfrr2q4 | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/05/01/6 | Mailing List Third Party Advisory |
Configurations
History
01 May 2026, 18:08
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Apache neethi
Apache |
|
| References | () https://lists.apache.org/thread/p826j0phhmr9f83wzpmys1y0bdfrr2q4 - Mailing List, Vendor Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/05/01/6 - Mailing List, Third Party Advisory | |
| CPE | cpe:2.3:a:apache:neethi:*:*:*:*:*:*:*:* |
01 May 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
01 May 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-01 09:16
Updated : 2026-05-01 18:08
NVD link : CVE-2026-42402
Mitre link : CVE-2026-42402
CVE.ORG link : CVE-2026-42402
JSON object : View
Products Affected
apache
- neethi
CWE
CWE-400
Uncontrolled Resource Consumption
