ALPHACON BBSGość · pl
← Podatności

Podatności / NVD · CVSS 4.3

CVE-2026-91867 · When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the cal…

Identyfikator
CVE-2026-91867
CVSS
4.3 MEDIUM
CISA KEV
nie ma w katalogu
Opublikowano
2026-09-21
When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.