Apache Neethi是Apache基金会的一个策略处理框架库。 Apache Neethi存在资源管理错误漏洞,该漏洞源于未正确检测策略定义中的循环引用,可能导致策略规范化过程进入无限循环或过度递归,导致堆栈溢出或应用挂起。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Neethi | < 3.2.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Neethi | 0 ~ 3.2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42778 | 9.8 CRITICAL | Apache MINA: CWE-502 Deserialization of Untrusted Data (take 2) |
| CVE-2026-42779 | 9.8 CRITICAL | Apache MINA: AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter |
| CVE-2026-42402 | 7.5 HIGH | Apache Neethi: Policy Normalization Unbounded Resource Allocation DoS |
| CVE-2026-42404 | 6.5 MEDIUM | Apache Neethi: Unrestricted HTTP Redirect Following in Policy References |
No comments yet