CVE-2026-42402

Source
https://cve.org/CVERecord?id=CVE-2026-42402
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42402.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-42402
Aliases
Downstream
Related
Published
2026-05-01T08:54:41.427Z
Modified
2026-08-12T03:51:32.265798589Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Apache Neethi: Policy Normalization Unbounded Resource Allocation DoS
Details

Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-product expansion during the normalization process, causing unbounded memory allocation that exhausts the JVM heap. This occurs when the normalization process generates an excessive number of policy alternatives without bounds, leading to runtime memory exhaustion.

Users should upgrade to 3.2.2 which limits the maximum number of normalized policy alternatives.

Database specific
{
    "cwe_ids": [
        "CWE-400"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42402.json",
    "cna_assigner": "apache",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "3.2.2"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/apache/ws-neethi

Affected ranges

Type
GIT
Repo
https://github.com/apache/ws-neethi
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:apache:neethi:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.2.2"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

Other
0_90@331547
0_90@374083
0_90@383288
1_01_RC@331547
1_01_RC@374083
1_01_RC@388355
1_01_RC@392334
1_0@331547
1_0@374083
1_0@388063
1_0_1@331547
1_0_1@374083
1_0_1@388355
1_0_1@398891
1_0_1@398892
2_0@331547
2_0@374083
2_0@388355
2_0@398891
2_0@474163
2_0_1@331547
2_0_1@374083
2_0_1@388355
2_0_1@398891
2_0_1@529482
2_0_2@331547
2_0_2@331547-
2_0_2@331547--
2_0_2@374083
2_0_2@374083-
2_0_2@374083--
2_0_2@388355
2_0_2@388355-
2_0_2@398891
2_0_2@398891-
2_0_2@553081
2_0_2@556647
2.*
2.0.3@331547
2.0.3@374083
2.0.3@388355
2.0.3@398891
2.0.3@646794
2.0.4@331547
2.0.4@374083
2.0.4@388355
2.0.4@398891
2.0.4@649060
2.0.5@331547
2.0.5@374083
2.0.5@388355
2.0.5@398891
2.0.5@787316
3.*
3.0.0@1088365
3.0.0@331547
3.0.0@374083
3.0.0@388355
3.0.0@398891
neethi-3.*
neethi-3.0.1@1145220
neethi-3.0.1@331547
neethi-3.0.1@374083
neethi-3.0.1@388355
neethi-3.0.1@398891
neethi-3.0.2@1310942
neethi-3.0.2@331547
neethi-3.0.2@374083
neethi-3.0.2@388355
neethi-3.0.2@398891
neethi-3.2.0
neethi-3.2.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42402.json"