SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-66142

HIGH · CVSS 7.5 EPSS 0.48%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

Apache Neethi is vulnerable to uncontrolled recursion when processing policies that either lack policy IDs or contain deeply nested structures, potentially leading to denial of service through runtime memory exhaustion. Organizations utilizing affected versions should prioritize upgrading to version 3.2.3 to mitigate this high-severity risk. This vulnerability is particularly critical for those relying on Apache Neethi for policy parsing in their applications.

CVE
CVE-2026-66142
Severity
HIGH
CVSS
7.5
EPSS
0.48%
Apache

Original NVD Description

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)