VYPR
High severity7.5NVD Advisory· Published Jul 24, 2026· Updated Jul 27, 2026

CVE-2026-66143

CVE-2026-66143

Description

It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue.

Affected products

2
  • Apache/Neethillm-fuzzy2 versions
    up to 3.2.2+ 1 more
    • (no CPE)range: up to 3.2.2
    • cpe:2.3:a:apache:neethi:3.2.2:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.