SEPTEMBER 25, 2026
Live Feed
Back to database
Case File

CVE-2026-91865

HIGH · CVSS 7.5 EPSS 0.49%

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-09-25

CyberRota Analysis

AI-Generated

The vulnerability allows a crafted WS-Policy document to cause Neethi to exponentially re-expand repeated policy references, leading to significant CPU and memory consumption that results in a denial of service. Organizations utilizing Neethi for policy management should prioritize this issue to prevent potential service disruptions. It is recommended to upgrade to version 3.2.4 to mitigate this risk.

CVE
CVE-2026-91865
Severity
HIGH
CVSS
7.5
EPSS
0.49%

Original NVD Description

A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)