SEPTEMBER 25, 2026
Live Feed
Back to database
Case File

CVE-2026-91863

HIGH · CVSS 7.5 EPSS 0.53%

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-09-25

CyberRota Analysis

AI-Generated

A denial-of-service vulnerability exists in Neethi due to its inability to handle deeply nested WS-Policy documents, allowing attackers to crash the parser by exhausting the thread stack. Organizations utilizing Neethi should prioritize upgrading to version 3.2.4 to mitigate this high-severity risk. This issue particularly affects environments where WS-Policy documents are processed, making it critical for users relying on this functionality to take immediate action.

CVE
CVE-2026-91863
Severity
HIGH
CVSS
7.5
EPSS
0.53%

Original NVD Description

A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)