CVE-2026-42404
published 2026-05-01CVE-2026-42404: Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application…
PriorityP348high7.2CVSS 3.1
AVNACLPRNUINSCCLILAN
EPSS
0.50%
39.2th percentile
Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden.
Users are recommended to upgrade to version 3.2.2, which fixes this issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | neethi | < 3.2.2 | 3.2.2 |
| apache | neethi | — | — |
| apache_software_foundation | apache_neethi | < 3.2.2 | 3.2.2 |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-287c-fxr7-3w6c: Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API
ghsa_unreviewed·2026-05-01
CVE-2026-42404 [MEDIUM] CWE-918 GHSA-287c-fxr7-3w6c: Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API
Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden.
Users are recommended to upgrade to version 3.2.2, which fixes this issue.
GHSA
Apache Neethi doesn't impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API
ghsa·2026-05-01
CVE-2026-42404 [MEDIUM] CWE-918 Apache Neethi doesn't impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API
Apache Neethi doesn't impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API
Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden.
Users are recommended to upgrade to version 3.2.2, which fixes this issue.
Red Hat
Apache Neethi: Apache Neethi: Information disclosure and network access bypass via PolicyReference API
vendor_redhat·2026-05-01·CVSS 7.2
CVE-2026-42404 [HIGH] CWE-918 Apache Neethi: Apache Neethi: Information disclosure and network access bypass via PolicyReference API
Apache Neethi: Apache Neethi: Information disclosure and network access bypass via PolicyReference API
A flaw was found in Apache Neethi. When an application explicitly calls the PolicyReference API to retrieve a policy from a remote Uniform Resource Identifier (URI), Apache Neethi does not impose restrictions on the URI. This allows a remote attacker to cause the application to make outbound requests to arbitrary protocols and internal IP addresses. This could lead to information disclosure or enable further network-based attacks.
Mitigation: To mitigate this issue, restrict outbound network access for applications that utilize Apache Neethi's PolicyReference API, especially if they process untrusted input that could influence the URI used for fetching remote policies. Implement firewal
No detection rules found.
No public exploits indexed.
2026-05-01
Published