{"id":"CVE-2026-91863","published":"2026-09-21T12:17:24.697","lastModified":"2026-09-21T18:10:30.343","description":"A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service).\nUsers are recommended to upgrade to version 3.2.4, which fixes this issue.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-674"],"vendors":[],"products":[],"references":[{"url":"https://lists.apache.org/thread/72kxj71lvrqqx90xxqqctvpbw0t8mpxw","tags":[]},{"url":"http://www.openwall.com/lists/oss-security/2026/09/18/10","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows a specially crafted WS-Policy document to exhaust the thread stack, causing a denial of service. This matters because it can disrupt service without requiring sophisticated exploitation.","exploitability":"Exploitation requires sending a complex WS-Policy document; preconditions include using an affected version of Neethi.","blast_radius":"If exploited, this could lead to service disruption for systems relying on the affected parser.","remediation":"Upgrade to Neethi version 3.2.4 immediately to address this issue.","tags":["dos","xml","policy","parser"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:11:22.525Z"}}