CVE-2026-42404
Last modified
CVE-2026-42404 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden. Users are recommended to upgrade to version 3.2.2, which fixes this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Neethi | < 3.2.2 |
References
- https://lists.apache.org/thread/zdspnt64zznyjyn648553kptx69w23oqIssue Tracking, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/05/01/8Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-42404?
How severe is CVE-2026-42404?
How do I fix CVE-2026-42404?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-42399Uncontrolled Resource Consumption (CWE-400) in Kibana can le…6.5
- CVE-2026-4240A vulnerability was determined in Open5GS up to 2.7.6. The a…7.5
- CVE-2026-42400Uncontrolled Resource Consumption (CWE-400) in Kibana can le…6.5
- CVE-2026-42401Improper Neutralization of Input During Web Page Generation …5.4
- CVE-2026-42402Apache Neethi is vulnerable to a Denial of Service attack th…7.5
- CVE-2026-42403Apache Neethi does not properly detect circular references i…7.5
- CVE-2026-42406A vulnerability exists in BIG-IP and BIG-IQ systems where a …8.7
- CVE-2026-42408When BIG-IP DNS is provisioned, a vulnerability exists in an…6.7
- CVE-2026-42409When an HTTP/2 profile and an iRule containing the HTTP::red…8.7
- CVE-2026-4241A vulnerability was identified in itsourcecode College Manag…6.3
- CVE-2026-42410Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2026-42411Unauthenticated Broken Authentication in CloudSecure WP Secu…8.1
Are you affected by CVE-2026-42404?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
