{"id":"CVE-2026-91865","published":"2026-09-21T12:17:24.903","lastModified":"2026-09-21T18:10:30.343","description":"A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service).\nUsers are recommended to upgrade to version 3.2.4, which fixes this issue.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-770"],"vendors":[],"products":[],"references":[{"url":"https://lists.apache.org/thread/l48btqh02rlpsgf5p6r5ltqk1cb69dtc","tags":[]},{"url":"http://www.openwall.com/lists/oss-security/2026/09/18/12","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw involves a small WS-Policy document that can cause Neethi to consume excessive CPU and memory during normalization, leading to a denial of service (DoS). This matters because it can disrupt system operations without requiring sophisticated exploitation techniques.","exploitability":"Exploitation is relatively easy as the attack vector relies on specific policy documents; no complex user interaction or advanced privileges are needed.","blast_radius":"If exploited, this could significantly impact system availability, affecting multiple services and potentially leading to service disruptions for users.","remediation":"Upgrade to Neethi version 3.2.4 to address the issue.","tags":["dos","policy-exploit","normalization-issue"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:11:43.602Z"}}