CVE-2026-91866

A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.

Credits

This issue was found using Claude agents to study the security of open-source projects

References