Vulnerability Description
It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Neethi | 3.2.2 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/s6o6p5pvcbcsk54dlg6j699t5gxol28wMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/24/9Mailing ListThird Party Advisory
FAQ
What is CVE-2026-66143?
CVE-2026-66143 is a vulnerability with a CVSS score of 7.5 (HIGH). It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via ...
How severe is CVE-2026-66143?
CVE-2026-66143 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-66143?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Neethi.