CVE-2026-102496
Last modified
CVE-2026-102496 is a vulnerability of currently unknown severity. Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue..
Description
Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Apache Software Foundation | Apache XMLSchema | < 2.3.3 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-102496?
How severe is CVE-2026-102496?
How do I fix CVE-2026-102496?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10247A vulnerability was found in SourceCodester Pharmacy Sales a…3.5
- CVE-2026-102473A flaw was found in dash. When built without libc fnmatch, t…5.5
- CVE-2026-102474A flaw was found in dash. The printf builtin reserves four b…4
- CVE-2026-10248A vulnerability was determined in SourceCodester Pharmacy Sa…4.7
- CVE-2026-10249A vulnerability was identified in itsourcecode Online Blood …7.3
- CVE-2026-102495Apache XmlSchema doesn't limit how deeply schema imports and…
- CVE-2026-102497The Apache XmlSchema walker (xmlschema-walker) doesn't detec…
- CVE-2026-1025IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2…6.1
- CVE-2026-10250A security flaw has been discovered in itsourcecode Online B…7.3
- CVE-2026-102507Sliver C2 framework version 1.7.7 and earlier contains an un…5.7
- CVE-2026-10251A weakness has been identified in itsourcecode Online House …7.3
- CVE-2026-10252A security vulnerability has been detected in itsourcecode O…7.3
Are you affected by CVE-2026-102496?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
