CyberRota Analysis
AI-GeneratedApache XmlSchema is vulnerable to a denial of service due to its lack of limits on the depth of nested schema imports and includes, allowing a malicious schema to cause stack overflow through excessive recursion. Organizations using affected versions should prioritize upgrading to version 2.3.3 to mitigate this risk.
CVE
CVE-2026-102495
Severity
HIGH
CVSS
7.5
EPSS
0.53%
Apache
Original NVD Description
Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)