CVE-2026-91865
HIGH
NVD
CVSS Score
7.5
Severity
HIGH
Published
Sep 21, 2026
Vendor
unknown
Description
A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.