---
id: CVE-2026-91866
title: >-
  A specially crafted pair of WS-Policy documents can force Neethi's
  policy-intersection to do exponential amounts of work, pinning the CPU for a
  long time (denial of service).

  Users are recommended to upgrade to version 3.2.4, which fixes…
summary: >-
  A specially crafted pair of WS-Policy documents can force Neethi's
  policy-intersection to do exponential amounts of work, pinning the CPU for a
  long time (denial of service).

  Users are recommended to upgrade to version 3.2.4, which fixes…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
  - CWE-1333
vendor: apache
product: neethi
affected:
  - neethi < 3.2.4
patched:
  - neethi 3.2.4
published: '2026-09-21'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T13:09:24.660'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91866'
references:
  - url: 'https://lists.apache.org/thread/zbfxnomgvbmqchqjgc6lk5h0z76k3gh4'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/18/13'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91866.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-91866'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2538243'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-91866'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91866'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00488
epssPercentile: 0.39413
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-21T13:16:11.074135Z'
ingestedAt: '2026-09-21T11:35:54.434Z'
---

## Overview

A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service).
Users are recommended to upgrade to version 3.2.4, which fixes this issue.

## Affected

- `neethi < 3.2.4`

## Remediation

Upgrade past the affected range:

- `neethi 3.2.4`

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, … · no fix planned: Red Hat JBoss Enterprise Application Platform 7, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Fuse 7, … · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91866.json)
