Apache XMLSchema

3 known vulnerabilities in Apache XMLSchema, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-102497 CVSS 7.5 high The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute…
  • CVE-2026-102496 CVSS 7.5 high Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make…
  • CVE-2026-102495 CVSS 7.5 high Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until…