CVE-2026-42403 HIGH

CVE-2026-42403: Apache Neethi: Circular Policy Reference Infinite Loop

Vendor Apache Software Foundation
Product Apache Neethi
Weakness CWE-400
Published May 1, 2026
Last update May 1, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (where Policy A references Policy B which references Policy A), the policy normalization process can enter an infinite loop or cause excessive recursion, leading to a stack overflow or application hang. An attacker can craft malicious policy documents with circular references to cause a Denial of Service condition Users are recommended to upgrade to version 3.2.2, which fixes this issue.

Key dates

02Disclosure timeline

May 1, 2026 CVE published
May 1, 2026 Record updated

Related vulnerabilities

04Related CVE