Back

HIGH

Apache XMLSchema: Denial of service through unbounded recursion when resolving schema imports and includes

Published Sep 29, 2026

Description

Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.

Affected products

Remediation

Red Hat statement

This flaw is rated as having an Important severity because unauthenticated remote attackers can crash application runtimes by submitting crafted definitions to services parsing untrusted XML schemas. In environments such as Red Hat JBoss Fuse or Enterprise Application Platform, services that dynamically resolve nested schema dependencies can experience JVM stack exhaustion and complete denial of service. The blast radius is limited to service availability, as the issue does not permit remote code execution or unauthorized data exposure.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

References (7)

Change history (2)
  1. Red Hat
    • mitigation

      changed from n/a to Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

    • statement

      changed from n/a to This flaw is rated as having an Important severity because unauthenticated remote attackers can crash application runtimes by submitting crafted definitions to services parsing untrusted XML schemas. In environments such as Red Hat JBoss Fuse or Enterprise Application Platform, services that dynamically resolve nested schema dependencies can experience JVM stack exhaustion and complete denial of service. The blast radius is limited to service availability, as the issue does not permit remote code execution or unauthorized data exposure.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Sep 29, 2026
Updated Sep 29, 2026
Reserved Sep 29, 2026
CISA Vulnrichment
Updated Sep 29, 2026
NVD
Status Analyzed
Modified Oct 6, 2026
Red Hat
Severity Important
Public date Sep 29, 2026
ENISA EUVD
Assigner apache
Published Sep 29, 2026
Updated Sep 29, 2026
Exploited since n/a
EUVD-2026-88737