{"id":"CVE-2026-91866","published":"2026-09-21T12:17:25.000","lastModified":"2026-09-21T18:10:30.343","description":"A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service).\nUsers are recommended to upgrade to version 3.2.4, which fixes this issue.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-770"],"vendors":[],"products":[],"references":[{"url":"https://lists.apache.org/thread/zbfxnomgvbmqchqjgc6lk5h0z76k3gh4","tags":[]},{"url":"http://www.openwall.com/lists/oss-security/2026/09/18/13","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw involves a denial of service vulnerability in Neethi's policy-intersection due to improperly handled WS-Policy documents, leading to excessive CPU usage.","exploitability":"Exploitation requires a specially crafted pair of WS-Policy documents and is considered moderate difficulty given the specific conditions needed.","blast_radius":"If exploited, this could significantly impact system performance, potentially disrupting services for all users.","remediation":"Upgrade to Neethi version 3.2.4 to address the vulnerability.","tags":["dos","ws-policy","neethi"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:11:54.304Z"}}