Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5376 articles · 221061 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-66142PATCHED
apache · neethi

Apache Neethi: Uncontrolled recursion in policy processing

Description

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue.

Affected Products

VendorProductVersions
apacheneethi0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ibmqradar siemcert_advisory90%
ibmwebsphere application server libertycert_advisory90%

References

  • https://lists.apache.org/thread/fomwtwt4pzzhxn4fyn3skykto913vfzt(vendor-advisory)

Related News (7 articles)

Tier B
CERT-FR4d ago
Multiples vulnérabilités dans les produits IBM (18 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR11d ago
Multiples vulnérabilités dans les produits IBM (11 septembre 2026)
→ No new info (linked only)
Tier B
BSI Advisories13d ago
[NEU] [mittel] IBM WebSphere Application Server Liberty: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR25d ago
Multiples vulnérabilités dans les produits IBM (28 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories26d ago
[NEU] [hoch] IBM QRadar SIEM: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB60d ago
CVE-2026-66142 | Apache Neethi up to 3.2.2 recursion
→ No new info (linked only)
Tier C
oss-security60d ago
CVE-2026-66142: Apache Neethi: Uncontrolled recursion in policy processing
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
3.2.3
CWECWE-400
PublishedJul 24, 2026
Last enriched60d ago
Trending Score33
Source articles7
Independent4
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-59084EXP
Apache Tomcat: EncryptInterceptor requirements not clearly documented
Trending: 42
CRITICALCVE-2026-59083EXP
Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
Trending: 42
CRITICALCVE-2026-66713
Apache Axis2/Java: deserialization of untrusted Data
Trending: 37
HIGHCVE-2026-50734
Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire memory-allocation DoS during wire format negotiation
Trending: 34
HIGHCVE-2026-64958
Apache CXF: Denial of service via message header attachments
Trending: 34

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 24, 2026
Discovered by ZDM
Jul 24, 2026
Patch Available
Jul 24, 2026