---
id: CVE-2026-91865
title: >-
  A small WS-Policy document using repeated policy references can force Neethi
  to re-expand the same references exponentially during normalization, consuming
  huge amounts of CPU and memory (denial of service).

  Users are recommended to upgr…
summary: >-
  A small WS-Policy document using repeated policy references can force Neethi
  to re-expand the same references exponentially during normalization, consuming
  huge amounts of CPU and memory (denial of service).

  Users are recommended to upgr…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
  - CWE-776
vendor: Apache Software Foundation
product: 'org.apache.neethi:neethi'
affected:
  - 'org.apache.neethi:neethi < 3.2.4'
published: '2026-09-21'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T18:10:30.343'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91865'
references:
  - url: 'https://lists.apache.org/thread/l48btqh02rlpsgf5p6r5ltqk1cb69dtc'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/18/12'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91865.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-91865'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2538975'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-91865'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91865'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-21T13:17:00.672389Z'
ingestedAt: '2026-09-21T11:35:54.436Z'
epss: 0.00514
epssPercentile: 0.42764
---

## Overview

A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service).
Users are recommended to upgrade to version 3.2.4, which fixes this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, … · no fix planned: Red Hat JBoss Enterprise Application Platform 7, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Fuse 7, … · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91865.json)
