When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service). Users are recommended to up
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Neethi | < 3.2.4 |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Neethi | 0 ~ 3.2.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94301 | 9.8 CRITICAL | Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2 |
| CVE-2026-47321 | 7.5 HIGH | Apache MINA: Unbounded Decompression Amplification DoS in Zlib.inflate |
| CVE-2026-91863 | Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows den | |
| CVE-2026-91864 | Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory | |
| CVE-2026-91865 | Apache Neethi: Crafted policy references cause exponential expansion during normalization | |
| CVE-2026-91866 | Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial | |
| CVE-2026-82355 | Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, en | |
| CVE-2026-75158 | Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag autho | |
| CVE-2026-86473 | Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocabl |
No comments yet