CVE-2026-102495 PUBLISHED

Apache XMLSchema: Denial of service through unbounded recursion when resolving schema imports and includes

Assigner: apache
Reserved: 29.09.2026 Published: 29.09.2026 Updated: 29.09.2026

Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.

Product Status

Vendor Apache Software Foundation
Product Apache XMLSchema
Versions Default: unaffected
  • affected from 0 to 2.3.3 (excl.)

Credits

  • This issue was found using Claude agents to study the security of open-source projects finder

References