Apache disclosed two high-severity denial-of-service vulnerabilities in Apache Neethi affecting versions before 3.2.2. CVE-2026-42402 allows specially crafted WS-Policy documents to trigger exponential Cartesian cross-product expansion during policy normalization, leading to unbounded memory allocation, JVM heap exhaustion, and application crashes or stalls. Apache said the issue is fixed in version 3.2.2 by limiting the maximum number of normalized policy alternatives.
Apache also disclosed CVE-2026-42403, which stems from improper detection of circular references in WS-Policy definitions. A malicious policy document can force infinite looping or excessive recursion during normalization, potentially causing stack overflows or application hangs. Apache recommends upgrading to 3.2.2 to address both flaws.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Apache publicly disclosed CVE-2026-42403, a high-severity denial-of-service vulnerability in Apache Neethi caused by improper handling of circular references in WS-Policy definitions. A malicious policy document can trigger infinite looping or excessive recursion during normalization, potentially causing stack overflow or application hangs.
Apache publicly disclosed CVE-2026-42402, a high-severity denial-of-service vulnerability in Apache Neethi caused by algorithmic complexity in WS-Policy normalization. Specially crafted policy documents can trigger exponential expansion, exhaust JVM heap memory, and crash or stall applications.
Apache addressed two high-severity denial-of-service flaws in Apache Neethi by releasing version 3.2.2 for affected versions before 3.2.2. The fixes mitigate unbounded resource allocation during WS-Policy normalization (CVE-2026-42402) and infinite looping from circular policy references (CVE-2026-42403).
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourcews.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.