CVE-2026-102497
Published 29 September 2026 · tracked since 29 September 2026
Description
The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute groups. A malicious schema with such a cycle can make the walker recurse until the stack overflows, causing a denial of service.Users are recommended to upgrade t
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-85520
- CVE-2026-95520 HIGH 7.1
- CVE-2026-66083
- CVE-2026-102495
- CVE-2026-102496
- CVE-2026-8937 MEDIUM 4.3
- CVE-2026-81862
- CVE-2026-81914
- CVE-2026-81930 MEDIUM 6.3
- CVE-2026-84739 HIGH 8.7