org.apache.ws.xmlschema:xmlschema-core vulnerabilities
CVEs whose affected-version data names the org.apache.ws.xmlschema:xmlschema-core package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-102496NoneApache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse until the stack overflows
Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended t…
▾ SunlitApache Software Foundation · org.apache.ws.xmlschema:xmlschema-corevia NVD
CVE-2026-102495NoneApache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows
Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2…
▾ SunlitApache Software Foundation · org.apache.ws.xmlschema:xmlschema-corevia NVD