Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3192 articles · 168085 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-42402EXPLOITEDPATCHED
apache · neethi

Apache Neethi: Policy Normalization Unbounded Resource Allocation DoS

Description

Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-product expansion during the normalization process, causing unbounded memory allocation that exhausts the JVM heap. This occurs when the normalization process generates an excessive number of policy alternatives without bounds, leading to runtime memory exhaustion. Users should upgrade to 3.2.2 which limits the maximum number of normalized policy alternatives.

Affected Products

VendorProductVersions
apacheneethimaven/org.apache.neethi:neethi: < 3.2.2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ibmwebsphere applicationcert_advisory90%
ibmwebsphere application server libertycert_advisory90%

References

  • https://lists.apache.org/thread/p826j0phhmr9f83wzpmys1y0bdfrr2q4(vendor-advisory)

Related News (3 articles)

Tier B
BSI Advisories3d ago
[NEU] [hoch] IBM WebSphere Application Server und Application Server Liberty: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security57d ago
CVE-2026-42402: Apache Neethi: Policy Normalization Unbounded Resource Allocation DoS
→ No new info (linked only)
Tier C
VulDB57d ago
CVE-2026-42402 | Apache Neethi up to 3.2.1 resource consumption
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
org.apache.neethi:neethi@3.2.2
CWECWE-400
PublishedMay 1, 2026
Last enriched57d agov3
Trending Score41
Source articles3
Independent3
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-49486EXP
Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT_P)
Trending: 59
MEDIUMCVE-2026-57914EXP
Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures
Trending: 45
HIGHCVE-2026-43870
Apache Thrift: Node.js web_server.js multi-vulnerability
Trending: 43
HIGHCVE-2026-57915
Apache Kerby: Kerberos Pre-Authentication Bypass
Trending: 42
HIGHCVE-2026-42403EXP
Apache Neethi: Circular Policy Reference Infinite Loop
Trending: 41

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 1, 2026
Discovered by ZDM
May 1, 2026
Updated: affectedVersions, severity, activelyExploited
May 1, 2026
Updated: affectedVersions, exploitAvailable
May 1, 2026
Actively Exploited
May 1, 2026
Exploit Available
May 1, 2026
Patch Available
May 1, 2026

Version History

v3
Last enriched 57d ago
v3Tier C57d ago

Updated affected versions to 'before 3.2.2', marked exploit as available, and set patch available to null.

affectedVersionsexploitAvailable
via oss-security
v2Tier C57d ago

Updated affected versions to include 3.2.1, changed severity to MEDIUM, and noted that no exploit is available.

affectedVersionsseverityactivelyExploited
via VulDB
v157d ago

Initial creation