---
id: CVE-2026-91863
title: >-
  A specially crafted WS-Policy document with deeply nested policy elements can
  bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the
  parser (denial of service).

  Users are recommended to upgrade to version 3.2.4, w…
summary: >-
  A specially crafted WS-Policy document with deeply nested policy elements can
  bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the
  parser (denial of service).

  Users are recommended to upgrade to version 3.2.4, w…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-674
  - CWE-835
vendor: apache
product: neethi
affected:
  - neethi < 3.2.4
patched:
  - neethi 3.2.4
published: '2026-09-21'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:34:14.977'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91863'
references:
  - url: 'https://lists.apache.org/thread/72kxj71lvrqqx90xxqqctvpbw0t8mpxw'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/18/10'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91863.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-91863'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2538446'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-91863'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91863'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00758
epssPercentile: 0.53306
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-21T13:35:51.992035Z'
ingestedAt: '2026-09-21T11:35:54.434Z'
---

## Overview

A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service).
Users are recommended to upgrade to version 3.2.4, which fixes this issue.

## Affected

- `neethi < 3.2.4`

## Remediation

Upgrade past the affected range:

- `neethi 3.2.4`

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, … · no fix planned: Red Hat JBoss Enterprise Application Platform 7, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Fuse 7, … · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91863.json)
