Back

HIGH

Apache XMLSchema: Denial of service through deeply nested schema structures

Published Sep 29, 2026

Description

Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.

Affected products

Remediation

Red Hat statement

This vulnerability is rated as Important severity because an unauthenticated remote attacker can cause a denial of service by supplying an excessively nested schema definition, leading to JVM stack exhaustion without requiring special privileges. In typical Red Hat deployments such as JBoss EAP and Red Hat build of Apache Camel, applications exposing web services or endpoints that process untrusted XML schemas can be crashed or rendered unavailable. Exploitation solely affects availability, with no impact to system integrity or confidentiality.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

References (7)

Change history (2)
  1. Red Hat
    • mitigation

      changed from n/a to Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

    • statement

      changed from n/a to This vulnerability is rated as Important severity because an unauthenticated remote attacker can cause a denial of service by supplying an excessively nested schema definition, leading to JVM stack exhaustion without requiring special privileges. In typical Red Hat deployments such as JBoss EAP and Red Hat build of Apache Camel, applications exposing web services or endpoints that process untrusted XML schemas can be crashed or rendered unavailable. Exploitation solely affects availability, with no impact to system integrity or confidentiality.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Sep 29, 2026
Updated Sep 29, 2026
Reserved Sep 29, 2026
CISA Vulnrichment
Updated Sep 29, 2026
NVD
Status Analyzed
Modified Oct 6, 2026
Red Hat
Severity Important
Public date Sep 29, 2026
ENISA EUVD
Assigner apache
Published Sep 29, 2026
Updated Sep 29, 2026
Exploited since n/a
EUVD-2026-88738