{"id":"CVE-2026-91864","published":"2026-09-21T12:17:24.807","lastModified":"2026-09-21T18:10:30.343","description":"A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service).\nUsers are recommended to upgrade to version 3.2.4, which fixes this issue.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-770"],"vendors":[],"products":[],"references":[{"url":"https://lists.apache.org/thread/400kbynbyhqhsjkv1yz251jm9wdz8z69","tags":[]},{"url":"http://www.openwall.com/lists/oss-security/2026/09/18/11","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows a specially crafted WS-Policy document to cause heap exhaustion due to unbounded content copying, leading to denial of service.","exploitability":"Exploitation requires crafting a large WS-Policy document; practicality depends on attacker's ability to deliver such content.","blast_radius":"If exploited, it could result in service disruption for affected systems.","remediation":"Upgrade to version 3.2.4 or later to mitigate the issue.","tags":["dos","ws-policy","memory-exhaustion"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:11:31.930Z"}}