CVE-2026-42402
published 2026-05-01CVE-2026-42402: Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.71%
49.5th percentile
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-product expansion during the normalization process, causing unbounded memory allocation that exhausts the JVM heap. This occurs when the normalization process generates an excessive number of policy alternatives without bounds, leading to runtime memory exhaustion.
Users should upgrade to 3.2.2 which limits the maximum number of normalized policy alternatives.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | neethi | < 3.2.2 | 3.2.2 |
| apache | neethi | — | — |
| apache_software_foundation | apache_neethi | < 3.2.2 | 3.2.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g36m-9g3m-2vmp: Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization
ghsa_unreviewed·2026-05-01
CVE-2026-42402 [HIGH] CWE-400 GHSA-g36m-9g3m-2vmp: Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-product expansion during the normalization process, causing unbounded memory allocation that exhausts the JVM heap. This occurs when the normalization process generates an excessive number of policy alternatives without bounds, leading to runtime memory exhaustion.
Users should upgrade to 3.2.2 which limits the maximum number of normalized policy alternatives.
GHSA
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization
ghsa·2026-05-01
CVE-2026-42402 [HIGH] CWE-400 Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-product expansion during the normalization process, causing unbounded memory allocation that exhausts the JVM heap. This occurs when the normalization process generates an excessive number of policy alternatives without bounds, leading to runtime memory exhaustion.
Users should upgrade to 3.2.2 which limits the maximum number of normalized policy alternatives.
Red Hat
org.apache.neethi: Apache Neethi: Denial of Service via algorithmic complexity in policy normalization
vendor_redhat·2026-05-01·CVSS 7.5
CVE-2026-42402 [HIGH] CWE-770 org.apache.neethi: Apache Neethi: Denial of Service via algorithmic complexity in policy normalization
org.apache.neethi: Apache Neethi: Denial of Service via algorithmic complexity in policy normalization
A flaw was found in Apache Neethi. A remote attacker can exploit this vulnerability by providing specially crafted WS-Policy documents. This triggers an algorithmic complexity issue during policy normalization, leading to an exponential expansion of policy alternatives. This unbounded memory allocation exhausts the Java Virtual Machine (JVM) heap, resulting in a Denial of Service (DoS) condition.
Statement: This flaw is rated Moderate because Apache Neethi, as used in Red Hat products, is susceptible to a denial of service. Remote attackers can provide malicious WS-Policy documents, leading to an algorithmic complexity issue during policy normalization. This results in unbounded memory
No detection rules found.
No public exploits indexed.
2026-05-01
Published