Apache XMLSchema: Denial of service through deeply nested schema structures
Published Sep 29, 2026
7.5
HIGHCVSS 3.1
EPSS 0.36%
Description
Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.
Affected products
-
- Version 0StatusaffectedConstraints<2.3.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache XMLSchema | unaffected |
|
No data.
Red Hat Fuse 7
xmlschema-core
Affected
Red Hat JBoss Enterprise Application Platform 7
jboss-eap-7/eap74-els-openjdk11-openshift-rhel8
Will not fix
Red Hat JBoss Enterprise Application Platform 7
jboss-eap-7/eap74-els-openjdk17-openshift-rhel8
Will not fix
Red Hat JBoss Enterprise Application Platform 7
jboss-eap-7/eap74-els-openjdk8-openshift-rhel8
Will not fix
Red Hat JBoss Enterprise Application Platform 7
xmlschema-core
Will not fix
Red Hat JBoss Enterprise Application Platform 8
xmlschema-core
Affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
xmlschema-core
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-spark-operator-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th-torch-cpu-py312-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th-torch-cuda-py312-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cpu-torch210-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cpu-torch291-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cuda130-torch210-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cuda130-torch291-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-rocm64-torch291-py312-rhel9
Not affected
Red Hat Single Sign-On 7
xmlschema-core
Affected
Red Hat build of Apache Camel 4 for Quarkus 3
xmlschema-core
Affected
Red Hat build of Apache Camel for Spring Boot 4
xmlschema-core
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7 | xmlschema-core | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk11-openshift-rhel8 | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk17-openshift-rhel8 | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk8-openshift-rhel8 | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | xmlschema-core | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | xmlschema-core | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | xmlschema-core | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-spark-operator-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th-torch-cpu-py312-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th-torch-cuda-py312-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cpu-torch210-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cpu-torch291-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cuda130-torch210-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cuda130-torch291-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-rocm64-torch291-py312-rhel9 | Not affected | n/a |
| Red Hat Single Sign-On 7 | xmlschema-core | Affected | n/a |
| Red Hat build of Apache Camel 4 for Quarkus 3 | xmlschema-core | Affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | xmlschema-core | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is rated as Important severity because an unauthenticated remote attacker can cause a denial of service by supplying an excessively nested schema definition, leading to JVM stack exhaustion without requiring special privileges. In typical Red Hat deployments such as JBoss EAP and Red Hat build of Apache Camel, applications exposing web services or endpoints that process untrusted XML schemas can be crashed or rendered unavailable. Exploitation solely affects availability, with no impact to system integrity or confidentiality.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (7)
- http://www.openwall.com/lists/oss-security/2026/09/29/16 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-102496 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2543086 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88738 Advisory
- https://lists.apache.org/thread/9z1vg8wmvwpfw748fb2nb55w4hgbnxol vendor-advisoryMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-102496
- https://www.cve.org/CVERecord?id=CVE-2026-102496
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/09/29/16 | Mailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2026-102496 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2543086 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88738 | Advisory | |
| https://lists.apache.org/thread/9z1vg8wmvwpfw748fb2nb55w4hgbnxol | vendor-advisoryMailing ListVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-102496 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-102496 |
Change history (2)
- Red Hat
mitigation
changed from n/a to Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.n/a → Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
statement
changed from n/a to This vulnerability is rated as Important severity because an unauthenticated remote attacker can cause a denial of service by supplying an excessively nested schema definition, leading to JVM stack exhaustion without requiring special privileges. In typical Red Hat deployments such as JBoss EAP and Red Hat build of Apache Camel, applications exposing web services or endpoints that process untrusted XML schemas can be crashed or rendered unavailable. Exploitation solely affects availability, with no impact to system integrity or confidentiality.n/a → This vulnerability is rated as Important severity because an unauthenticated remote attacker can cause a denial of service by supplying an excessively nested schema definition, leading to JVM stack exhaustion without requiring special privileges. In typical Red Hat deployments such as JBoss EAP and Red Hat build of Apache Camel, applications exposing web services or endpoints that process untrusted XML schemas can be crashed or rendered unavailable. Exploitation solely affects availability, with no impact to system integrity or confidentiality.