CVE WATCH / VULNERABILITY DETAIL

CVE-2026-102495

UNKNOWNCVSS 0NVD feed

Published 29 September 2026 · tracked since 29 September 2026

Description

Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-102495 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-102495

UNKNOWNCVSS 0NVD feed

Published 29 September 2026 · tracked since 29 September 2026

Description

Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]