Apache Neethi是Apache基金会的一个策略处理框架库。 Apache Neethi存在资源管理错误漏洞,该漏洞源于策略规范化中的算法复杂性,可能导致特制WS-Policy文档触发指数级笛卡尔积扩展,导致内存耗尽。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Neethi | < 3.2.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Neethi | 0 ~ 3.2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42778 | 9.8 CRITICAL | Apache MINA: CWE-502 Deserialization of Untrusted Data (take 2) |
| CVE-2026-42779 | 9.8 CRITICAL | Apache MINA: AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter |
| CVE-2026-42403 | 7.5 HIGH | Apache Neethi: Circular Policy Reference Infinite Loop |
| CVE-2026-42404 | 6.5 MEDIUM | Apache Neethi: Unrestricted HTTP Redirect Following in Policy References |
No comments yet