[
https://issues.apache.org/jira/browse/CXF-9254?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Andriy Redko updated CXF-9254:
------------------------------
Fix Version/s: 4.2.4
> Shipped xmlschema-core : 2.3.2 is vulnerable (CVE-2026-102495)
> --------------------------------------------------------------
>
> Key: CXF-9254
> URL: https://issues.apache.org/jira/browse/CXF-9254
> Project: CXF
> Issue Type: Bug
> Components: Core
> Affects Versions: 4.2.3
> Reporter: Benjamin Marwell
> Priority: Major
> Fix For: 4.2.4
>
>
> h2. Issue description
> Latest CXF Core has a dependency to xmlschema-core:
> {code}
> [INFO] +- org.apache.cxf:cxf-rt-rs-client:jar:4.2.3:runtime
> [INFO] | +- org.apache.cxf:cxf-rt-transports-http:jar:4.2.3:runtime
> [INFO] | +- org.apache.cxf:cxf-core:jar:4.2.3:runtime
> [INFO] | | +- jakarta.annotation:jakarta.annotation-api:jar:2.1.1:runtime
> [INFO] | | +- org.glassfish.jaxb:jaxb-runtime:jar:4.0.9:runtime
> [INFO] | | | \- org.glassfish.jaxb:jaxb-core:jar:4.0.9:runtime
> [INFO] | | | +- org.glassfish.jaxb:txw2:jar:4.0.9:runtime
> [INFO] | | | \- com.sun.istack:istack-commons-runtime:jar:4.1.2:runtime
> [INFO] | | +- com.fasterxml.woodstox:woodstox-core:jar:7.2.1:runtime
> [INFO] | | | \- org.codehaus.woodstox:stax2-api:jar:4.3.0:runtime
> [INFO] | | +- org.apache.ws.xmlschema:xmlschema-core:jar:2.3.2:runtime
> [INFO] | | +- org.eclipse.angus:angus-activation:jar:2.0.3:runtime
> [INFO] | | | \- jakarta.activation:jakarta.activation-api:jar:2.1.0:runtime
> [INFO] | | \- jakarta.xml.bind:jakarta.xml.bind-api:jar:4.0.0:runtime
> [INFO] | \- org.apache.cxf:cxf-rt-frontend-jaxrs:jar:4.2.3:test
> [INFO] | \- org.apache.cxf:cxf-rt-security:jar:4.2.3:test
> {code}
> h2. Proposed fix
> Upgrade to 2.3.3
> h2. Sonatype Information
> *Issue*: CVE-2026-102495
> *Description from CVE*: Apache XmlSchema doesn't limit how deeply schema
> imports and includes can be nested, so a malicious schema can make parsing
> recurse until the stack overflows. This causes a denial of service. Users are
> recommended to upgrade to version 2.3.3, which fixes this issue.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)