CVE-2026-91864
7.5 HIGHPublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows a specially crafted WS-Policy document to cause heap exhaustion due to unbounded content copying, leading to denial of service.
- Exploitability
- Exploitation requires crafting a large WS-Policy document; practicality depends on attacker's ability to deliver such content.
- Blast radius
- If exploited, it could result in service disruption for affected systems.
- Prioritized remediation
- Upgrade to version 3.2.4 or later to mitigate the issue.
dosws-policymemory-exhaustion
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-770
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- LOWCVE-2026-85219PoC
- HIGHCVE-2026-91866
- HIGHCVE-2026-47321
- HIGHCVE-2026-61483
- HIGHCVE-2026-63252PoC
- HIGHCVE-2026-94626PoC
- HIGHCVE-2026-59675PoC
- HIGHCVE-2026-61629PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.