CVE-2026-102495
- EPSS 0.36%
- Veröffentlicht 29.09.2026 12:17:09
- Zuletzt bearbeitet 06.10.2026 14:38:53
Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which f...
CVE-2026-102496
- EPSS 0.36%
- Veröffentlicht 29.09.2026 12:17:09
- Zuletzt bearbeitet 06.10.2026 14:38:42
Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to ...
CVE-2026-102497
- EPSS 0.36%
- Veröffentlicht 29.09.2026 12:17:09
- Zuletzt bearbeitet 06.10.2026 14:37:44
The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute groups. A malicious schema with such a cycle can make the walker recurse until the stack overflows, causing a deni...