Home

Description

Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden. Users are recommended to upgrade to version 3.2.2, which fixes this issue.

PUBLISHED Reserved 2026-04-27 | Published 2026-05-01 | Updated 2026-05-01 | Assigner apache




MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Problem types

CWE-918 Server-Side Request Forgery (SSRF)

Product status

Default status
unaffected

Any version before 3.2.2
affected

References

lists.apache.org/thread/zdspnt64zznyjyn648553kptx69w23oq vendor-advisory

cve.org (CVE-2026-42404)

nvd.nist.gov (CVE-2026-42404)

Download JSON