CVE-2026-42404

MEDIUM

Apache Neethi: Unrestricted HTTP Redirect Following in Policy References

Title source: cna
STIX 2.1

Description

Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application explicitly calls the API to retrieve a policy from a remote URI, an outbound request is made for arbitrary protocols and internal IP adddresses. From 3.2.2, only http or https URIs are allowed, and link-local/multicast/any-local addresses are forbidden. Users are recommended to upgrade to version 3.2.2, which fixes this issue.

Scores

CVSS v3 6.5
EPSS 0.0003
EPSS Percentile 7.4%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
Apache Software Foundation/Apache Neethi < 3.2.2
Published May 01, 2026
Tracked Since May 01, 2026