Apache Neethi是Apache基金会的一个策略处理框架库。 Apache Neethi存在代码问题漏洞,该漏洞源于通过PolicyReference API手动获取远程策略引用时未对URI施加限制,可能导致对任意协议和内部IP地址发出出站请求。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Neethi | < 3.2.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Neethi | 0 ~ 3.2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42778 | 9.8 CRITICAL | Apache MINA: CWE-502 Deserialization of Untrusted Data (take 2) |
| CVE-2026-42779 | 9.8 CRITICAL | Apache MINA: AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter |
| CVE-2026-42402 | 7.5 HIGH | Apache Neethi: Policy Normalization Unbounded Resource Allocation DoS |
| CVE-2026-42403 | 7.5 HIGH | Apache Neethi: Circular Policy Reference Infinite Loop |
No comments yet