Denial of Service Vulnerability in Apache XmlSchema Walker
CVE-2026-102497

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 September 2026

What is CVE-2026-102497?

The Apache XmlSchema walker component fails to identify cyclical structures in type derivation, substitution groups, model groups, or attribute groups. This oversight can be exploited by an attacker using a maliciously crafted XML schema, leading to uncontrolled recursion that results in a stack overflow, thereby causing a denial of service. Users are strongly advised to upgrade to version 2.3.3 or later to mitigate this vulnerability.

Affected Version(s)

Apache XMLSchema 0 < 2.3.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was found using Claude agents to study the security of open-source projects
.