CVE-2026-91867

Source
https://cve.org/CVERecord?id=CVE-2026-91867
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91867.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-91867
Published
2026-09-21T11:27:45Z
Modified
2026-09-27T03:47:29Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely
Details

When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.

Database specific
{
    "cna_assigner":  "apache",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91867.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "fixed":  "3.2.4"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/apache/ws-neethi

Affected ranges

Type
GIT
Repo
https://github.com/apache/ws-neethi
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:apache:neethi:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "3.2.4"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

Other
0_90@331547
0_90@374083
0_90@383288
1_01_RC@331547
1_01_RC@374083
1_01_RC@388355
1_01_RC@392334
1_0@331547
1_0@374083
1_0@388063
1_0_1@331547
1_0_1@374083
1_0_1@388355
1_0_1@398891
1_0_1@398892
2_0@331547
2_0@374083
2_0@388355
2_0@398891
2_0@474163
2_0_1@331547
2_0_1@374083
2_0_1@388355
2_0_1@398891
2_0_1@529482
2_0_2@331547
2_0_2@331547-
2_0_2@331547--
2_0_2@374083
2_0_2@374083-
2_0_2@374083--
2_0_2@388355
2_0_2@388355-
2_0_2@398891
2_0_2@398891-
2_0_2@553081
2_0_2@556647
2.*
2.0.3@331547
2.0.3@374083
2.0.3@388355
2.0.3@398891
2.0.3@646794
2.0.4@331547
2.0.4@374083
2.0.4@388355
2.0.4@398891
2.0.4@649060
2.0.5@331547
2.0.5@374083
2.0.5@388355
2.0.5@398891
2.0.5@787316
3.*
3.0.0@1088365
3.0.0@331547
3.0.0@374083
3.0.0@388355
3.0.0@398891
neethi-3.*
neethi-3.0.1@1145220
neethi-3.0.1@331547
neethi-3.0.1@374083
neethi-3.0.1@388355
neethi-3.0.1@398891
neethi-3.0.2@1310942
neethi-3.0.2@331547
neethi-3.0.2@374083
neethi-3.0.2@388355
neethi-3.0.2@398891
neethi-3.2.0
neethi-3.2.1
neethi-3.2.2
neethi-3.2.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91867.json"