{
  "threat_severity" : "Moderate",
  "public_date" : "2026-05-01T09:46:49Z",
  "bugzilla" : {
    "description" : "Apache Neethi: Apache Neethi: Information disclosure and network access bypass via PolicyReference API",
    "id" : "2464324",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2464324"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-918",
  "details" : [ "A flaw was found in Apache Neethi. When an application explicitly calls the PolicyReference API to retrieve a policy from a remote Uniform Resource Identifier (URI), Apache Neethi does not impose restrictions on the URI. This allows a remote attacker to cause the application to make outbound requests to arbitrary protocols and internal IP addresses. This could lead to information disclosure or enable further network-based attacks." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Build of Apache Camel 4.14 for Quarkus 3.27",
    "release_date" : "2026-05-20T00:00:00Z",
    "advisory" : "RHSA-2026:19835",
    "cpe" : "cpe:/a:redhat:apache_camel_quarkus:3.27",
    "package" : "neethi"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat build of Apache Camel 4 for Quarkus 3",
    "fix_state" : "Affected",
    "package_name" : "neethi",
    "cpe" : "cpe:/a:redhat:camel_quarkus:3"
  }, {
    "product_name" : "Red Hat build of Apache Camel for Spring Boot 4",
    "fix_state" : "Fix deferred",
    "package_name" : "neethi",
    "cpe" : "cpe:/a:redhat:camel_spring_boot:4"
  }, {
    "product_name" : "Red Hat Fuse 7",
    "fix_state" : "Fix deferred",
    "package_name" : "neethi",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7",
    "fix_state" : "Fix deferred",
    "package_name" : "neethi",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8",
    "fix_state" : "Fix deferred",
    "package_name" : "neethi",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform Expansion Pack",
    "fix_state" : "Fix deferred",
    "package_name" : "neethi",
    "cpe" : "cpe:/a:redhat:jbosseapxp"
  }, {
    "product_name" : "Red Hat Process Automation 7",
    "fix_state" : "Fix deferred",
    "package_name" : "neethi",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
  }, {
    "product_name" : "Red Hat Single Sign-On 7",
    "fix_state" : "Fix deferred",
    "package_name" : "neethi",
    "cpe" : "cpe:/a:redhat:red_hat_single_sign_on:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-42404\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-42404\nhttps://lists.apache.org/thread/zdspnt64zznyjyn648553kptx69w23oq" ],
  "name" : "CVE-2026-42404",
  "mitigation" : {
    "value" : "To mitigate this issue, restrict outbound network access for applications that utilize Apache Neethi's PolicyReference API, especially if they process untrusted input that could influence the URI used for fetching remote policies. Implement firewall rules or network policies to limit the protocols and IP addresses to which the application can connect. This may impact application functionality if legitimate remote policy fetching is required.",
    "lang" : "en:us"
  },
  "csaw" : false
}