What is CVE-2026-66143?
CVE-2026-66143: In Apache Neethi, the maximum number of normalized policy alternatives introduced in version 3.2.2 can be bypassed using specially crafted policies. This may lead to a denial of service (DoS) attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue.
Azərbaycanca: CVE-2026-66143: Apache Neethi 3.2.2-də təqdim edilən maksimum normallaşdırılmış siyasət alternativ limiti xüsusi hazırlanmış policy-lər vasitəsilə keçilə bilər. Bu, resurs istehlakı nəticəsində denial of service (DoS) hücumuna səbəb ola bilər. İstifadəçilərə problemi aradan qaldıran 3.2.3 versiyasına yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
Which version of Apache Neethi is affected by CVE-2026-66143?
This vulnerability affects Apache Neethi version 3.2.2, as the maximum normalized policy alternative limit was introduced in this version.
What is the recommended solution for Apache Neethi users regarding CVE-2026-66143?
Users are recommended to upgrade to version 3.2.3, which fixes this denial of service (DoS) vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.