CVE-2026-102495: Apache XMLSchema: Denial of service through unbounded recursion when resolving schema imports and includes
Published Sep 29, 2026
·Updated
Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.
Affected Software
1 affected component
Apache XMLSchema<2.3.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache XMLSchemato a version that resolves this vulnerability.Fixed in 2.3.3
Event History
Sep 29, 2026
CVE Published
via MITRE·11:33 AM
Data Sourced
via MITRE·11:33 AM
Description
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What must an attacker be able to do to trigger the denial of service?
An attacker needs to cause Apache XMLSchema to parse a malicious schema containing deeply nested imports or includes. The resulting unbounded recursion can overflow the stack and deny service.
2
What remediation is available?
Upgrade Apache XMLSchema to version 2.3.3, which fixes the issue.