Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3192 articles · 168085 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-42403EXPLOITEDPATCHED
apache · neethi

Apache Neethi: Circular Policy Reference Infinite Loop

Description

Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (where Policy A references Policy B which references Policy A), the policy normalization process can enter an infinite loop or cause excessive recursion, leading to a stack overflow or application hang. An attacker can craft malicious policy documents with circular references to cause a Denial of Service condition Users are recommended to upgrade to version 3.2.2, which fixes this issue.

Affected Products

VendorProductVersions
apacheneethimaven/org.apache.neethi:neethi: < 3.2.2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ibmwebsphere applicationcert_advisory90%
ibmwebsphere application server libertycert_advisory90%

References

  • https://lists.apache.org/thread/zm6t8skkkskjwk1881l4m4n0l7dqclzo(vendor-advisory)

Related News (3 articles)

Tier B
BSI Advisories3d ago
[NEU] [hoch] IBM WebSphere Application Server und Application Server Liberty: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security57d ago
CVE-2026-42403: Apache Neethi: Circular Policy Reference Infinite Loop
→ No new info (linked only)
Tier C
VulDB57d ago
CVE-2026-42403 | Apache Neethi up to 3.2.1 resource consumption
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
org.apache.neethi:neethi@3.2.2
CWECWE-400
PublishedMay 1, 2026
Last enriched57d agov3
Trending Score41
Source articles3
Independent3
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-49486EXP
Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT_P)
Trending: 59
MEDIUMCVE-2026-57914EXP
Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures
Trending: 45
HIGHCVE-2026-43870
Apache Thrift: Node.js web_server.js multi-vulnerability
Trending: 43
HIGHCVE-2026-57915
Apache Kerby: Kerberos Pre-Authentication Bypass
Trending: 42
HIGHCVE-2026-42402EXP
Apache Neethi: Policy Normalization Unbounded Resource Allocation DoS
Trending: 41

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 1, 2026
Discovered by ZDM
May 1, 2026
Updated: affectedVersions
May 1, 2026
Updated: affectedVersions, exploitAvailable, activelyExploited
May 1, 2026
Actively Exploited
May 1, 2026
Exploit Available
May 1, 2026
Patch Available
May 1, 2026

Version History

v3
Last enriched 57d ago
v3Tier C57d ago

Updated affected versions to 'before 3.2.2' and marked exploit availability and active exploitation as true.

affectedVersionsexploitAvailableactivelyExploited
via oss-security
v2Tier C57d ago

Updated affected versions to include 3.2.1 and noted that no exploit exists.

affectedVersions
via VulDB
v157d ago

Initial creation