Vulnerability Details CVE-2026-66142
Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial of service attack when parsing policies due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3, which fixes this issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 25.3%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-66142
-
cpe:2.3:a:apache:neethi:0.90
-
cpe:2.3:a:apache:neethi:1.0
-
cpe:2.3:a:apache:neethi:1.0.1
-
cpe:2.3:a:apache:neethi:1.01
-
cpe:2.3:a:apache:neethi:2.0
-
cpe:2.3:a:apache:neethi:2.0.1
-
cpe:2.3:a:apache:neethi:2.0.2
-
cpe:2.3:a:apache:neethi:2.0.3
-
cpe:2.3:a:apache:neethi:2.0.4
-
cpe:2.3:a:apache:neethi:2.0.5
-
cpe:2.3:a:apache:neethi:3.0.0
-
cpe:2.3:a:apache:neethi:3.0.1
-
cpe:2.3:a:apache:neethi:3.0.2
-
cpe:2.3:a:apache:neethi:3.0.3
-
cpe:2.3:a:apache:neethi:3.1.0
-
cpe:2.3:a:apache:neethi:3.1.1
-
cpe:2.3:a:apache:neethi:3.2.0
-
cpe:2.3:a:apache:neethi:3.2.1
-
cpe:2.3:a:apache:neethi:3.2.2