---
id: CVE-2026-91864
title: >-
  A specially crafted WS-Policy document can pack unlimited content inside a
  policy assertion, which Neethi copies into memory without counting it against
  its size limits, exhausting the heap (denial of service).

  Users are recommended to u…
summary: >-
  A specially crafted WS-Policy document can pack unlimited content inside a
  policy assertion, which Neethi copies into memory without counting it against
  its size limits, exhausting the heap (denial of service).

  Users are recommended to u…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
vendor: Apache Software Foundation
product: 'org.apache.neethi:neethi'
affected:
  - 'org.apache.neethi:neethi < 3.2.4'
published: '2026-09-21'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T18:10:30.343'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91864'
references:
  - url: 'https://lists.apache.org/thread/400kbynbyhqhsjkv1yz251jm9wdz8z69'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/18/11'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-21T13:27:33.548043Z'
ingestedAt: '2026-09-21T11:35:54.433Z'
---

## Overview

A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service).
Users are recommended to upgrade to version 3.2.4, which fixes this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
