Loading market data...
← Back to CVE feed

CVE-2026-91865

HIGH CVSS 7.5 View on NVD ↗

Description

A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Published: Sep 21, 2026 12:17 UTC Modified: Sep 21, 2026 18:10 UTC