OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102497

HIGH · CVSS 7.5 EPSS 0.53%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The Apache XmlSchema walker is vulnerable to denial of service due to its failure to detect cycles in type derivation and other schema constructs, which can lead to stack overflow through excessive recursion. Organizations using affected versions of Apache should prioritize upgrading to version 2.3.3 to mitigate this risk and ensure system stability. This vulnerability poses a significant threat to applications relying on XML schema processing, particularly in environments where malicious schemas could be introduced.

CVE
CVE-2026-102497
Severity
HIGH
CVSS
7.5
EPSS
0.53%
Apache

Original NVD Description

The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute groups. A malicious schema with such a cycle can make the walker recurse until the stack overflows, causing a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)