OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102496

HIGH · CVSS 7.5 EPSS 0.53%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Apache XmlSchema is vulnerable to a denial of service attack due to its inability to limit the depth of nested schema structures during parsing, potentially leading to stack overflow. Organizations utilizing Apache XmlSchema should prioritize upgrading to version 2.3.3 to mitigate this risk and ensure system stability.

CVE
CVE-2026-102496
Severity
HIGH
CVSS
7.5
EPSS
0.53%
Apache

Original NVD Description

Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)