Vulnerabilities
Vulnerable Software
Apache:  >> Xmlschema  >> 2.2.3  Security Vulnerabilities
Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.
CVSS Score
7.5
EPSS Score
0.005
Published
2026-09-29
Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.
CVSS Score
7.5
EPSS Score
0.005
Published
2026-09-29
The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute groups. A malicious schema with such a cycle can make the walker recurse until the stack overflows, causing a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.
CVSS Score
7.5
EPSS Score
0.005
Published
2026-09-29


Contact Us

Shodan ® - All rights reserved