CVE-2026-66143

Source
https://cve.org/CVERecord?id=CVE-2026-66143
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66143.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-66143
Published
2026-07-24T12:07:52Z
Modified
2026-09-11T11:47:09Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Apache Neethi: Missing global alternative-output budget across policy computation paths
Details

It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue.

Database specific
{
    "cna_assigner": "apache",
    "cwe_ids": [
        "CWE-400"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66143.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "3.2.3"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/apache/ws-neethi

Affected ranges

Type
GIT
Repo
https://github.com/apache/ws-neethi
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:apache:neethi:3.2.2:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.2.2"
        },
        {
            "last_affected": "3.2.2"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

3.*
3.2.2
neethi-3.*
neethi-3.2.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66143.json"