HIGH7.5CVE-2026-42403Apache Neethi does not properly detect circular references in policy definitions.
from 0, < 3.2.2
HIGH7.5CVE-2026-42402Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization
from 0, < 3.2.2
MEDIUM6.5CVE-2026-42404Apache Neethi doesn't impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API