Vulnerability Bulletins |
CVE-2026-66143 |
|
| Affected software | APACHE |
| It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may lead to a denial of service attack via resource consumption. Users are recommended to upgrade to version 3.2.3, which fixes this issue. | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-66143 | |






