SEPTEMBER 25, 2026
Live Feed
Back to database
Case File

CVE-2026-91867

MEDIUM · CVSS 4.3 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-09-25

CyberRota Analysis

AI-Generated

The vulnerability affects Neethi's handling of remote policy references, allowing an attacker to exploit the time limitation on reads, potentially leading to a denial of service by keeping the fetch operation alive indefinitely. This can result in resource exhaustion as the calling thread remains tied up. Organizations utilizing Neethi should prioritize upgrading to version 3.2.4 to mitigate this risk.

CVE
CVE-2026-91867
Severity
MEDIUM
CVSS
4.3
EPSS
0.33%

Original NVD Description

When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)