What is CVE-2026-66142?
Apache Neethi is vulnerable to uncontrolled recursion when parsing policies lacking policy Ids or with deeply nested structures. This can lead to a denial of service attack due to runtime memory exhaustion. Users are recommended to upgrade to version 3.2.3 to fix the issue.
Azərbaycanca: Apache Neethi kitabxanasında policy Id-ləri olmayan və ya dərin nested strukturları parse edərkən nəzarətsiz rekursiya zəifliyi aşkarlanıb. Bu, denial of service (DoS) vəziyyətinə və runtime memory tükənməsinə səbəb ola bilər. İstifadəçilərə 3.2.3 versiyasına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
Through what mechanism can the CVE-2026-66142 vulnerability in Apache Neethi lead to a Denial of Service?
This vulnerability can lead to a Denial of Service (DoS) attack due to runtime memory exhaustion caused by uncontrolled recursion when parsing policies lacking policy Ids or with deeply nested structures.
Which version are users recommended to upgrade to in order to fix CVE-2026-66142?
Users are recommended to upgrade to Apache Neethi version 3.2.3 to fix this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.