product of apache
neethi
Severity
Being told
The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.
Every thing
| When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes… CVE-2026-91867 | Severity medium |
| Neethi: Neethi: Denial of Service via crafted WS-Policy documents CVE-2026-91866 | Severity high |
| org.apache.neethi/neethi: Apache Neethi: Denial of Service via crafted WS-Policy documents CVE-2026-91865 | Severity high |
| org.apache.neethi/neethi: Apache Neethi: Denial of Service via crafted WS-Policy documents CVE-2026-91864 | Severity high |
| org.apache.neethi/neethi: Apache Neethi: Denial of Service via uncontrolled recursion in WS-Policy document parsing CVE-2026-91863 | Severity high |