Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vfqj-r56j-g77w

Опубликовано: 24 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue.

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue.

EPSS

Процентиль: 39%
0.00478
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
nvd
14 дней назад

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue.

EPSS

Процентиль: 39%
0.00478
Низкий

7.5 High

CVSS3

Дефекты

CWE-400