Skip to main content
Vulnerability Database/CVE-2026-91864

CVE-2026-91864: Apache Neethi WS-Policy DOS Vulnerability

CVE-2026-91864 is a denial of service vulnerability in Apache Neethi that allows attackers to exhaust heap memory via crafted WS-Policy documents. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-91864 Overview

CVE-2026-91864 is a denial-of-service vulnerability in Apache Neethi, the WS-Policy framework used by Apache Axis2 and related Web Services stacks. A specially crafted WS-Policy document can embed unlimited content inside a policy assertion. Neethi copies that content into memory without counting it against configured size limits, exhausting the heap. The flaw is categorized under [CWE-770: Allocation of Resources Without Limits or Throttling]. Remote, unauthenticated attackers can trigger the condition by submitting a malicious policy document to any service that parses WS-Policy input. Users are advised to upgrade to Apache Neethi version 3.2.4, which enforces the missing size accounting.

Critical Impact

Unauthenticated network attackers can exhaust process memory on any service that parses WS-Policy documents with Apache Neethi, causing service unavailability without requiring credentials or user interaction.

Affected Products

  • Apache Neethi versions prior to 3.2.4
  • Apache Axis2 and downstream SOAP/Web Services stacks that embed Neethi for WS-Policy processing
  • Any Java service that parses attacker-controlled WS-Policy documents via Neethi

Discovery Timeline

  • 2026-09-21 - CVE-2026-91864 published to the National Vulnerability Database (NVD)
  • 2026-09-21 - Last updated in NVD database

Technical Details for CVE-2026-91864

Vulnerability Analysis

Apache Neethi parses WS-Policy XML documents and materializes policy assertions as in-memory objects. The library enforces size limits intended to bound resource consumption when processing untrusted input. The vulnerability arises because content nested inside a policy assertion is copied into memory without being counted against those limits.

An attacker can pack an arbitrarily large payload inside a single assertion. Neethi accepts the document, allocates memory to hold the assertion body, and continues copying until the Java Virtual Machine (JVM) heap is exhausted. The process then throws OutOfMemoryError or becomes unresponsive under garbage collection pressure. The impact is limited to availability, with no confidentiality or integrity effect, consistent with the vector C:N/I:N/A:H.

Root Cause

The root cause is missing input accounting during assertion deserialization. Neethi enforces size caps at the document boundary but does not propagate those checks into the routine that copies assertion content. This is a classic [CWE-770] allocation-without-throttling defect: trusted-looking structural boundaries hide untrusted-length payloads.

Attack Vector

Exploitation requires only network access to an endpoint that accepts WS-Policy input. No authentication or user interaction is needed. An attacker submits a SOAP request or standalone policy document containing a policy assertion whose body is padded to hundreds of megabytes or larger. The victim service parses the document with Neethi, allocates memory to hold the assertion, and exhausts the JVM heap. Repeated requests amplify the impact and can take down clusters where each node parses a fresh copy of the payload.

No verified proof-of-concept code has been published. See the Apache Mailing List Thread and the Openwall OSS Security Update for maintainer details.

Detection Methods for CVE-2026-91864

Indicators of Compromise

  • Repeated java.lang.OutOfMemoryError: Java heap space entries in Axis2 or Neethi-backed service logs correlated with inbound SOAP requests.
  • Unusually large HTTP request bodies (tens of megabytes or more) delivered to endpoints that accept WS-Policy or SOAP payloads.
  • Sudden JVM heap saturation and full garbage-collection loops on services that expose WS-Policy processing.

Detection Strategies

  • Inspect application logs for stack traces originating from org.apache.neethi classes during policy parsing failures.
  • Enable request-size logging on the web tier and alert on WS-Policy or SOAP payloads exceeding an established baseline.
  • Correlate memory-pressure metrics with request patterns to identify single-source floods targeting policy endpoints.

Monitoring Recommendations

  • Track JVM heap utilization, full-GC frequency, and OutOfMemoryError counts on services that embed Neethi.
  • Monitor inbound request-body size distributions at the reverse proxy or Web Application Firewall (WAF).
  • Alert on process restarts or health-check failures on Axis2 nodes following spikes in policy-endpoint traffic.

How to Mitigate CVE-2026-91864

Immediate Actions Required

  • Upgrade Apache Neethi to version 3.2.4 on all affected services, including transitive dependencies pulled in by Axis2 and other WS-* stacks.
  • Inventory Java services that parse WS-Policy documents and identify shaded or bundled copies of Neethi that require separate patching.
  • Enforce request-body size limits at the reverse proxy or WAF for endpoints that accept SOAP or WS-Policy input.

Patch Information

The Apache Neethi maintainers fixed CVE-2026-91864 in version 3.2.4. The release enforces size accounting for content copied out of policy assertions. Refer to the Apache Mailing List Thread for the maintainer announcement and the Openwall OSS Security Update for the coordinated disclosure notice.

Workarounds

  • Cap inbound request sizes on the ingress layer to a value well below available JVM heap for services that cannot be patched immediately.
  • Restrict WS-Policy processing endpoints to authenticated peers or internal networks where feasible.
  • Configure the JVM with conservative heap limits and rapid restart policies so a single exhaustion event does not cascade across a cluster.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.