{"id":"CVE-2026-91867","published":"2026-09-21T12:17:25.107","lastModified":"2026-09-21T18:10:30.343","description":"When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service).\nUsers are recommended to upgrade to version 3.2.4, which fixes this issue.","cvssScore":4.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","cwes":["CWE-400"],"vendors":[],"products":[],"references":[{"url":"https://lists.apache.org/thread/dsr2ktf199mqhw2jtlbklyz7tzd86ycd","tags":[]},{"url":"http://www.openwall.com/lists/oss-security/2026/09/18/14","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw in Neethi allows a server to perform a denial of service by trickling bytes slowly during policy reference fetches, tying up the calling thread indefinitely.","exploitability":"Exploitation requires control over a remote server that can trickle data slowly, making it moderately difficult.","blast_radius":"If exploited, this could lead to service disruptions for affected systems using Neethi.","remediation":"Upgrade to Neethi version 3.2.4 to address the issue.","tags":["dos","thread-tie-up","policy-fetch"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:31:42.691Z"}}