CVE-2026-102495
Received Received - Intake

Apache XmlSchema Stack Overflow via Recursive Schema Imports

Vulnerability report for CVE-2026-102495, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Apache Software Foundation

Description

Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache xmlschema 2.3.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Apache XmlSchema allowing unlimited nesting of schema imports and includes. A malicious schema can trigger excessive recursion during parsing, leading to a stack overflow and causing a denial of service.

Detection Guidance

This vulnerability can be detected by checking the version of Apache XmlSchema in use. If you are running a version prior to 2.3.3, the system is vulnerable. Commands to check the version depend on your environment and how XmlSchema is integrated.

Impact Analysis

The vulnerability can disrupt services by crashing applications that parse schemas, leading to downtime or degraded performance. Systems using affected Apache XmlSchema versions are vulnerable to targeted attacks.

Compliance Impact

This vulnerability causes a denial of service by crashing the parser through stack overflow, which could disrupt services handling sensitive data. For GDPR, this may impact availability of personal data processing systems. For HIPAA, it could affect the integrity and availability of protected health information systems. Downtime or service disruption may lead to compliance violations if critical systems become unavailable.

Mitigation Strategies

Immediately upgrade Apache XmlSchema to version 2.3.3 or later to fix the stack overflow issue caused by deep schema imports and includes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102495. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart