Skip to content

Apache XMLSchema: denial of service

High7.5CVE-2026-102497 · Published Sep 29, 2026

The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute groups. A malicious schema with such a cycle can make the walker recurse until the stack overflows, causing a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.

Affected versions

PackageAffectedFixed in
Apache XMLSchema
Product
< 2.3.32.3.3
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache Polaris: missing authorization
High8.1Sep 29
Apache DolphinScheduler: improper authorization
Medium4.3Sep 29
Apache DolphinScheduler: missing authorization
Medium6.5Sep 29
Apache DolphinScheduler: authentication bypass
Medium5.3Sep 29
Apache DolphinScheduler: improper authorization
Medium4.3Sep 29
Apache DolphinScheduler: improper authorization
Medium4.3Sep 29

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.