CVE-2026-42402

Source
https://cve.org/CVERecord?id=CVE-2026-42402
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42402.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-42402
Aliases
Downstream
Related
Published
2026-05-01T08:54:41.427Z
Modified
2026-09-04T11:45:44.782380645Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Apache Neethi: Policy Normalization Unbounded Resource Allocation DoS
Details

Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-product expansion during the normalization process, causing unbounded memory allocation that exhausts the JVM heap. This occurs when the normalization process generates an excessive number of policy alternatives without bounds, leading to runtime memory exhaustion.

Users should upgrade to 3.2.2 which limits the maximum number of normalized policy alternatives.

Database specific
{
    "cwe_ids": [
        "CWE-400"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42402.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "3.2.2"
                }
            ]
        }
    ],
    "cna_assigner": "apache"
}
References

Affected packages

Git / github.com/apache/ws-neethi

Affected ranges

Type
GIT
Repo
https://github.com/apache/ws-neethi
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:apache:neethi:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.2.2"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42402.json"