CVE-2026-42404

Source
https://cve.org/CVERecord?id=CVE-2026-42404
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42404.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-42404
Aliases
Downstream
Related
Published
2026-05-01T09:46:49.958Z
Modified
2026-07-29T03:30:41.622138026Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Apache Neethi: Unrestricted HTTP Redirect Following in Policy References
Details

Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden.

Users are recommended to upgrade to version 3.2.2, which fixes this issue.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "3.2.2"
                }
            ]
        }
    ],
    "cna_assigner": "apache",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42404.json"
}
References

Affected packages

Git / github.com/apache/ws-neethi

Affected ranges

Type
GIT
Repo
https://github.com/apache/ws-neethi
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:apache:neethi:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.2.2"
        }
    ]
}

Affected versions

Other
0_90@331547
0_90@374083
0_90@383288
1_01_RC@331547
1_01_RC@374083
1_01_RC@388355
1_01_RC@392334
1_0@331547
1_0@374083
1_0@388063
1_0_1@331547
1_0_1@374083
1_0_1@388355
1_0_1@398891
1_0_1@398892
2_0@331547
2_0@374083
2_0@388355
2_0@398891
2_0@474163
2_0_1@331547
2_0_1@374083
2_0_1@388355
2_0_1@398891
2_0_1@529482
2_0_2@331547
2_0_2@331547-
2_0_2@331547--
2_0_2@374083
2_0_2@374083-
2_0_2@374083--
2_0_2@388355
2_0_2@388355-
2_0_2@398891
2_0_2@398891-
2_0_2@553081
2_0_2@556647
2.*
2.0.3@331547
2.0.3@374083
2.0.3@388355
2.0.3@398891
2.0.3@646794
2.0.4@331547
2.0.4@374083
2.0.4@388355
2.0.4@398891
2.0.4@649060
2.0.5@331547
2.0.5@374083
2.0.5@388355
2.0.5@398891
2.0.5@787316
3.*
3.0.0@1088365
3.0.0@331547
3.0.0@374083
3.0.0@388355
3.0.0@398891
neethi-3.*
neethi-3.0.1@1145220
neethi-3.0.1@331547
neethi-3.0.1@374083
neethi-3.0.1@388355
neethi-3.0.1@398891
neethi-3.0.2@1310942
neethi-3.0.2@331547
neethi-3.0.2@374083
neethi-3.0.2@388355
neethi-3.0.2@398891
neethi-3.2.0
neethi-3.2.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42404.json"