CVE-2026-102497None▾ SunlitThe Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute groups. A malicious schema with such a cycle can make the walker recurse until the stack overflows, c…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute groups. A malicious schema with such a cycle can make the walker recurse until the stack overflows, causing a denial of service.
Users are recommended to upgrade to version 2.3.3, which fixes this issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-81569NoneApache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized Workflow Execution
CVE-2026-78214NoneApache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths
CVE-2026-71899NoneApache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to Information Disclosure
CVE-2026-71898NoneApache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute Workflows and Tamper with Workflow Definitions
CVE-2026-71897NoneApache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and batch-move endpoints
CVE-2026-82804NoneThe scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this behavior by creating…