OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-91865 (CVSS 7.5)

NVD · officialPublished Sep 21, 2026Risk 23/100

A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.

CVSS
7.5
AV:NetworkAC:LowPR:NoneUI:NoneC:NoneI:NoneA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source