CVE WATCH / VULNERABILITY DETAIL

CVE-2026-102497

UNKNOWNCVSS 0NVD feed

Published 29 September 2026 · tracked since 29 September 2026

Description

The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute groups. A malicious schema with such a cycle can make the walker recurse until the stack overflows, causing a denial of service.Users are recommended to upgrade t

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-102497 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-102497

UNKNOWNCVSS 0NVD feed

Published 29 September 2026 · tracked since 29 September 2026

Description

The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute groups. A malicious schema with such a cycle can make the walker recurse until the stack overflows, causing a denial of service.Users are recommended to upgrade t

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]