Denial of Service Vulnerability in Apache XmlSchema
CVE-2026-102495

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 September 2026

What is CVE-2026-102495?

Apache XmlSchema contains a flaw where the depth of nested schema imports and includes is not limited, leading to potential denial of service. An attacker could craft a malicious schema that causes excessive recursion during parsing, ultimately resulting in a stack overflow. It is crucial for users to upgrade to version 2.3.3 to mitigate this vulnerability and ensure system stability.

Affected Version(s)

Apache XMLSchema 0 < 2.3.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was found using Claude agents to study the security of open-source projects
.