Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42403

Опубликовано: 01 мая 2026
Источник: redhat
CVSS3: 6.5

Описание

Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (where Policy A references Policy B which references Policy A), the policy normalization process can enter an infinite loop or cause excessive recursion, leading to a stack overflow or application hang. An attacker can craft malicious policy documents with circular references to cause a Denial of Service condition Users are recommended to upgrade to version 3.2.2, which fixes this issue.

A flaw was found in Apache Neethi. An attacker can exploit this vulnerability by crafting malicious WS-Policy documents that contain circular policy references. This can cause the policy normalization process to enter an infinite loop or excessive recursion, leading to a stack overflow or application hang. Consequently, a remote attacker can trigger a Denial of Service (DoS) condition.

Отчет

This Moderate flaw in Apache Neethi allows a remote attacker to trigger a Denial of Service condition. By crafting malicious WS-Policy documents with circular references, an attacker can cause the policy normalization process to enter an infinite loop or excessive recursion, leading to application instability or a hang. This can disrupt services relying on Apache Neethi for policy processing. In order to exploit this vulnerability, the attack should have enough privileges in the targeted system to include the maliciously crafted policy document or trick the user to consume it.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel 4 for Quarkus 3neethiAffected
Red Hat build of Apache Camel for Spring Boot 4neethiFix deferred
Red Hat Fuse 7neethiFix deferred
Red Hat JBoss Enterprise Application Platform 7neethiFix deferred
Red Hat JBoss Enterprise Application Platform 8neethiFix deferred
Red Hat JBoss Enterprise Application Platform Expansion PackneethiFix deferred
Red Hat Process Automation 7neethiFix deferred
Red Hat Single Sign-On 7neethiFix deferred
Red Hat Build of Apache Camel 4.14 for Quarkus 3.27neethiFixedRHSA-2026:1983520.05.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-606
https://bugzilla.redhat.com/show_bug.cgi?id=2464314org.apache.neethi: Apache Neethi: Denial of Service via circular policy references

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
3 месяца назад

Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (where Policy A references Policy B which references Policy A), the policy normalization process can enter an infinite loop or cause excessive recursion, leading to a stack overflow or application hang. An attacker can craft malicious policy documents with circular references to cause a Denial of Service condition Users are recommended to upgrade to version 3.2.2, which fixes this issue.

CVSS3: 7.5
github
3 месяца назад

Apache Neethi does not properly detect circular references in policy definitions.

6.5 Medium

CVSS3