cve-2026-42404
MEDIUM CVSS 5.3 csaf_redhat
Description
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
Timeline
- Published
- 2026-05-01 09:46 UTC
- Last Modified
- 2026-07-30
CVSS Details
CVSS details not available.
Affected Products
No product information available.
Weaknesses (CWE)
References
No references available.
Linked Vulnerabilities
{
"document": {
"aggregate_severity": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"text": "Moderate"
},
"category": "csaf_vex",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright © Red Hat, Inc. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "legal_disclaimer",
"text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
"title": "Terms of Use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://access.redhat.com/security/team/contact/",
"issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
"name": "Red Hat Product Security",
"namespace": "https://www.redhat.com"
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42404.json"
}
],
"title": "Apache Neethi: Apache Neethi: Information disclosure and network access bypass via PolicyReference API",
"tracking": {
"current_release_date": "2026-07-30T01:42:20+00:00",
"generator": {
"date": "2026-07-30T01:42:20+00:00",
"engine": {
"name": "Red Hat SDEngine",
"version": "5.3.8"
}
},
"id": "CVE-2026-42404",
"initial_release_date": "2026-05-01T09:46:49.958000+00:00",
"revision_history": [
{
"date": "2026-05-01T09:46:49.958000+00:00",
"number": "1",
"summary": "Initial version"
},
{
"date": "2026-05-18T13:40:39+00:00",
"number": "2",
"summary": "Current version"
},
{
"date": "2026-07-30T01:42:20+00:00",
"number": "3",
"summary": "Last generated version"
}
],
"status": "final",
"version": "3"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_name",
"name": "Red Hat build of Apache Camel 4 for Quarkus 3",
"product": {
"name": "Red Hat build of Apache Camel 4 for Quarkus 3",
"product_id": "red_hat_build_of_apache_camel_4_for_quarkus_3",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:camel_quarkus:3"
}
}
}
],
"category": "product_family",
"name": "Red Hat build of Apache Camel 4 for Quarkus 3"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat build of Apache Camel for Spring Boot 4",
"product": {
"name": "Red Hat build of Apache Camel for Spring Boot 4",
"product_id": "red_hat_build_of_apache_camel_for_spring_boot_4",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:camel_spring_boot:4"
}
}
}
],
"category": "product_family",
"name": "Red Hat build of Apache Camel for Spring Boot 4"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat Fuse 7",
"product": {
"name": "Red Hat Fuse 7",
"product_id": "red_hat_fuse_7",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:jboss_fuse:7"
}
}
}
],
"category": "product_family",
"name": "Red Hat Fuse 7"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat JBoss Enterprise Application Platform 7",
"product": {
"name": "Red Hat JBoss Enterprise Application Platform 7",
"product_id": "red_hat_jboss_enterprise_application_platform_7",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7"
}
}
}
],
"category": "product_family",
"name": "Red Hat JBoss Enterprise Application Platform 7"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat JBoss Enterprise Application Platform 8",
"product": {
"name": "Red Hat JBoss Enterprise Application Platform 8",
"product_id": "red_hat_jboss_enterprise_application_platform_8",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:8"
}
}
}
],
"category": "product_family",
"name": "Red Hat JBoss Enterprise Application Platform 8"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
"product": {
"name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
"product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:jbosseapxp"
}
}
}
],
"category": "product_family",
"name": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat Process Automation 7",
"product": {
"name": "Red Hat Process Automation 7",
"product_id": "red_hat_process_automation_7",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
}
}
}
],
"category": "product_family",
"name": "Red Hat Process Automation 7"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat Single Sign-On 7",
"product": {
"name": "Red Hat Single Sign-On 7",
"product_id": "red_hat_single_sign-on_7",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:red_hat_single_sign_on:7"
}
}
}
],
"category": "product_family",
"name": "Red Hat Single Sign-On 7"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat Build of Apache Camel 4.14 for Quarkus 3.27",
"product": {
"name": "Red Hat Build of Apache Camel 4.14 for Quarkus 3.27",
"product_id": "Red Hat Build of Apache Camel 4.14 for Quarkus 3.27",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:apache_camel_quarkus:3.27"
}
}
}
],
"category": "product_family",
"name": "Red Hat Build of Apache Camel"
},
{
"category": "product_version",
"name": "neethi",
"product": {
"name": "neethi",
"product_id": "neethi",
"product_identification_helper": {
"purl": "pkg:maven/org.apache.neethi/neethi"
}
}
}
],
"category": "vendor",
"name": "Red Hat"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "neethi as a component of Red Hat build of Apache Camel 4 for Quarkus 3",
"product_id": "red_hat_build_of_apache_camel_4_for_quarkus_3:neethi"
},
"product_reference": "neethi",
"relates_to_product_reference": "red_hat_build_of_apache_camel_4_for_quarkus_3"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "neethi as a component of Red Hat build of Apache Camel for Spring Boot 4",
"product_id": "red_hat_build_of_apache_camel_for_spring_boot_4:neethi"
},
"product_reference": "neethi",
"relates_to_product_reference": "red_hat_build_of_apache_camel_for_spring_boot_4"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "neethi as a component of Red Hat Fuse 7",
"product_id": "red_hat_fuse_7:neethi"
},
"product_reference": "neethi",
"relates_to_product_reference": "red_hat_fuse_7"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "neethi as a component of Red Hat JBoss Enterprise Application Platform 7",
"product_id": "red_hat_jboss_enterprise_application_platform_7:neethi"
},
"product_reference": "neethi",
"relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_7"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "neethi as a component of Red Hat JBoss Enterprise Application Platform 8",
"product_id": "red_hat_jboss_enterprise_application_platform_8:neethi"
},
"product_reference": "neethi",
"relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_8"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "neethi as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack",
"product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack:neethi"
},
"product_reference": "neethi",
"relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_expansion_pack"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "neethi as a component of Red Hat Process Automation 7",
"product_id": "red_hat_process_automation_7:neethi"
},
"product_reference": "neethi",
"relates_to_product_reference": "red_hat_process_automation_7"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "neethi as a component of Red Hat Single Sign-On 7",
"product_id": "red_hat_single_sign-on_7:neethi"
},
"product_reference": "neethi",
"relates_to_product_reference": "red_hat_single_sign-on_7"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-42404",
"cwe": {
"id": "CWE-918",
"name": "Server-Side Request Forgery (SSRF)"
},
"discovery_date": "2026-05-01T11:01:06.738996+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2464324"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in Apache Neethi. When an application explicitly calls the PolicyReference API to retrieve a policy from a remote Uniform Resource Identifier (URI), Apache Neethi does not impose restrictions on the URI. This allows a remote attacker to cause the application to make outbound requests to arbitrary protocols and internal IP addresses. This could lead to information disclosure or enable further network-based attacks.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "Apache Neethi: Apache Neethi: Information disclosure and network access bypass via PolicyReference API",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"fixed": [
"Red Hat Build of Apache Camel 4.14 for Quarkus 3.27"
],
"known_affected": [
"red_hat_build_of_apache_camel_4_for_quarkus_3:neethi",
"red_hat_build_of_apache_camel_for_spring_boot_4:neethi",
"red_hat_fuse_7:neethi",
"red_hat_jboss_enterprise_application_platform_7:neethi",
"red_hat_jboss_enterprise_application_platform_8:neethi",
"red_hat_jboss_enterprise_application_platform_expansion_pack:neethi",
"red_hat_process_automation_7:neethi",
"red_hat_single_sign-on_7:neethi"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-42404"
},
{
"category": "external",
"summary": "RHBZ#2464324",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2464324"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-42404",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-42404"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-42404",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42404"
},
{
"category": "external",
"summary": "https://lists.apache.org/thread/zdspnt64zznyjyn648553kptx69w23oq",
"url": "https://lists.apache.org/thread/zdspnt64zznyjyn648553kptx69w23oq"
}
],
"release_date": "2026-05-01T09:46:49.958000+00:00",
"remediations": [
{
"category": "vendor_fix",
"date": "2026-05-20T20:47:38+00:00",
"details": "Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.\nThe References section of this erratum contains a download link (you must log in to download the update).",
"product_ids": [
"Red Hat Build of Apache Camel 4.14 for Quarkus 3.27"
],
"url": "https://access.redhat.com/errata/RHSA-2026:19835"
},
{
"category": "workaround",
"details": "To mitigate this issue, restrict outbound network access for applications that utilize Apache Neethi's PolicyReference API, especially if they process untrusted input that could influence the URI used for fetching remote policies. Implement firewall rules or network policies to limit the protocols and IP addresses to which the application can connect. This may impact application functionality if legitimate remote policy fetching is required.",
"product_ids": [
"Red Hat Build of Apache Camel 4.14 for Quarkus 3.27",
"red_hat_build_of_apache_camel_4_for_quarkus_3:neethi",
"red_hat_build_of_apache_camel_for_spring_boot_4:neethi",
"red_hat_fuse_7:neethi",
"red_hat_jboss_enterprise_application_platform_7:neethi",
"red_hat_jboss_enterprise_application_platform_8:neethi",
"red_hat_jboss_enterprise_application_platform_expansion_pack:neethi",
"red_hat_process_automation_7:neethi",
"red_hat_single_sign-on_7:neethi"
]
},
{
"category": "none_available",
"details": "Fix deferred",
"product_ids": [
"red_hat_build_of_apache_camel_for_spring_boot_4:neethi",
"red_hat_fuse_7:neethi",
"red_hat_jboss_enterprise_application_platform_7:neethi",
"red_hat_jboss_enterprise_application_platform_8:neethi",
"red_hat_jboss_enterprise_application_platform_expansion_pack:neethi",
"red_hat_process_automation_7:neethi",
"red_hat_single_sign-on_7:neethi"
]
},
{
"category": "none_available",
"details": "Affected",
"product_ids": [
"red_hat_build_of_apache_camel_4_for_quarkus_3:neethi"
]
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"Red Hat Build of Apache Camel 4.14 for Quarkus 3.27",
"red_hat_build_of_apache_camel_4_for_quarkus_3:neethi",
"red_hat_build_of_apache_camel_for_spring_boot_4:neethi",
"red_hat_fuse_7:neethi",
"red_hat_jboss_enterprise_application_platform_7:neethi",
"red_hat_jboss_enterprise_application_platform_8:neethi",
"red_hat_jboss_enterprise_application_platform_expansion_pack:neethi",
"red_hat_process_automation_7:neethi",
"red_hat_single_sign-on_7:neethi"
]
}
],
"threats": [
{
"category": "impact",
"details": "Moderate",
"product_ids": [
"Red Hat Build of Apache Camel 4.14 for Quarkus 3.27",
"red_hat_build_of_apache_camel_4_for_quarkus_3:neethi",
"red_hat_build_of_apache_camel_for_spring_boot_4:neethi",
"red_hat_fuse_7:neethi",
"red_hat_jboss_enterprise_application_platform_7:neethi",
"red_hat_jboss_enterprise_application_platform_8:neethi",
"red_hat_jboss_enterprise_application_platform_expansion_pack:neethi",
"red_hat_process_automation_7:neethi",
"red_hat_single_sign-on_7:neethi"
]
}
],
"title": "Apache Neethi: Apache Neethi: Information disclosure and network access bypass via PolicyReference API"
}
]
}
Enrichment data
Aggregated bundle (all enrichments)