Apache XMLSchema: Denial of service through unbounded recursion when resolving schema imports and includes
Published Sep 29, 2026
7.5
HIGHCVSS 3.1
EPSS 0.36%
Description
Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.
Affected products
-
- Version 0StatusaffectedConstraints<2.3.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache XMLSchema | unaffected |
|
No data.
Red Hat Fuse 7
xmlschema-core
Affected
Red Hat JBoss Enterprise Application Platform 7
jboss-eap-7/eap74-els-openjdk11-openshift-rhel8
Will not fix
Red Hat JBoss Enterprise Application Platform 7
jboss-eap-7/eap74-els-openjdk17-openshift-rhel8
Will not fix
Red Hat JBoss Enterprise Application Platform 7
jboss-eap-7/eap74-els-openjdk8-openshift-rhel8
Will not fix
Red Hat JBoss Enterprise Application Platform 7
xmlschema-core
Will not fix
Red Hat JBoss Enterprise Application Platform 8
xmlschema-core
Affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
xmlschema-core
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-spark-operator-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th-torch-cpu-py312-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th-torch-cuda-py312-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cpu-torch210-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cpu-torch291-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cuda130-torch210-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cuda130-torch291-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-rocm64-torch291-py312-rhel9
Not affected
Red Hat Single Sign-On 7
xmlschema-core
Affected
Red Hat build of Apache Camel 4 for Quarkus 3
xmlschema-core
Affected
Red Hat build of Apache Camel for Spring Boot 4
xmlschema-core
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7 | xmlschema-core | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk11-openshift-rhel8 | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk17-openshift-rhel8 | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk8-openshift-rhel8 | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | xmlschema-core | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | xmlschema-core | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | xmlschema-core | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-spark-operator-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th-torch-cpu-py312-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th-torch-cuda-py312-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cpu-torch210-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cpu-torch291-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cuda130-torch210-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cuda130-torch291-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-rocm64-torch291-py312-rhel9 | Not affected | n/a |
| Red Hat Single Sign-On 7 | xmlschema-core | Affected | n/a |
| Red Hat build of Apache Camel 4 for Quarkus 3 | xmlschema-core | Affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | xmlschema-core | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw is rated as having an Important severity because unauthenticated remote attackers can crash application runtimes by submitting crafted definitions to services parsing untrusted XML schemas. In environments such as Red Hat JBoss Fuse or Enterprise Application Platform, services that dynamically resolve nested schema dependencies can experience JVM stack exhaustion and complete denial of service. The blast radius is limited to service availability, as the issue does not permit remote code execution or unauthorized data exposure.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (7)
- http://www.openwall.com/lists/oss-security/2026/09/29/15 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-102495 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2543083 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88737 Advisory
- https://lists.apache.org/thread/l339q3oldm0cd2lph4b6f93fd07x9g6s vendor-advisoryMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-102495
- https://www.cve.org/CVERecord?id=CVE-2026-102495
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/09/29/15 | Mailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2026-102495 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2543083 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88737 | Advisory | |
| https://lists.apache.org/thread/l339q3oldm0cd2lph4b6f93fd07x9g6s | vendor-advisoryMailing ListVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-102495 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-102495 |
Change history (2)
- Red Hat
mitigation
changed from n/a to Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.n/a → Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
statement
changed from n/a to This flaw is rated as having an Important severity because unauthenticated remote attackers can crash application runtimes by submitting crafted definitions to services parsing untrusted XML schemas. In environments such as Red Hat JBoss Fuse or Enterprise Application Platform, services that dynamically resolve nested schema dependencies can experience JVM stack exhaustion and complete denial of service. The blast radius is limited to service availability, as the issue does not permit remote code execution or unauthorized data exposure.n/a → This flaw is rated as having an Important severity because unauthenticated remote attackers can crash application runtimes by submitting crafted definitions to services parsing untrusted XML schemas. In environments such as Red Hat JBoss Fuse or Enterprise Application Platform, services that dynamically resolve nested schema dependencies can experience JVM stack exhaustion and complete denial of service. The blast radius is limited to service availability, as the issue does not permit remote code execution or unauthorized data exposure.