← Back to search

CVE-2026-91867

4.3 MEDIUM

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw in Neethi allows a server to perform a denial of service by trickling bytes slowly during policy reference fetches, tying up the calling thread indefinitely.
Exploitability
Exploitation requires control over a remote server that can trickle data slowly, making it moderately difficult.
Blast radius
If exploited, this could lead to service disruptions for affected systems using Neethi.
Prioritized remediation
Upgrade to Neethi version 3.2.4 to address the issue.
dosthread-tie-uppolicy-fetch

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Weaknesses

CWE-400

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.