Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden.
Users are recommended to upgrade to version 3.2.2, which fixes this issue.
Users are recommended to upgrade to version 3.2.2, which fixes this issue.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 01 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden. Users are recommended to upgrade to version 3.2.2, which fixes this issue. | |
| Title | Apache Neethi: Unrestricted HTTP Redirect Following in Policy References | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-05-01T09:46:49.958Z
Reserved: 2026-04-27T10:34:58.951Z
Link: CVE-2026-42404
No data.
Status : Received
Published: 2026-05-01T11:16:19.230
Modified: 2026-05-01T11:16:19.230
Link: CVE-2026-42404
No data.
OpenCVE Enrichment
No data.
Weaknesses