[ 
https://issues.apache.org/jira/browse/CXF-9254?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Andriy Redko updated CXF-9254:
------------------------------
    Fix Version/s: 4.2.4

> Shipped xmlschema-core : 2.3.2 is vulnerable (CVE-2026-102495)
> --------------------------------------------------------------
>
>                 Key: CXF-9254
>                 URL: https://issues.apache.org/jira/browse/CXF-9254
>             Project: CXF
>          Issue Type: Bug
>          Components: Core
>    Affects Versions: 4.2.3
>            Reporter: Benjamin Marwell
>            Priority: Major
>             Fix For: 4.2.4
>
>
> h2. Issue description
> Latest CXF Core has a dependency to xmlschema-core:
> {code}
> [INFO] +- org.apache.cxf:cxf-rt-rs-client:jar:4.2.3:runtime
> [INFO] |  +- org.apache.cxf:cxf-rt-transports-http:jar:4.2.3:runtime
> [INFO] |  +- org.apache.cxf:cxf-core:jar:4.2.3:runtime
> [INFO] |  |  +- jakarta.annotation:jakarta.annotation-api:jar:2.1.1:runtime
> [INFO] |  |  +- org.glassfish.jaxb:jaxb-runtime:jar:4.0.9:runtime
> [INFO] |  |  |  \- org.glassfish.jaxb:jaxb-core:jar:4.0.9:runtime
> [INFO] |  |  |     +- org.glassfish.jaxb:txw2:jar:4.0.9:runtime
> [INFO] |  |  |     \- com.sun.istack:istack-commons-runtime:jar:4.1.2:runtime
> [INFO] |  |  +- com.fasterxml.woodstox:woodstox-core:jar:7.2.1:runtime
> [INFO] |  |  |  \- org.codehaus.woodstox:stax2-api:jar:4.3.0:runtime
> [INFO] |  |  +- org.apache.ws.xmlschema:xmlschema-core:jar:2.3.2:runtime
> [INFO] |  |  +- org.eclipse.angus:angus-activation:jar:2.0.3:runtime
> [INFO] |  |  |  \- jakarta.activation:jakarta.activation-api:jar:2.1.0:runtime
> [INFO] |  |  \- jakarta.xml.bind:jakarta.xml.bind-api:jar:4.0.0:runtime
> [INFO] |  \- org.apache.cxf:cxf-rt-frontend-jaxrs:jar:4.2.3:test
> [INFO] |     \- org.apache.cxf:cxf-rt-security:jar:4.2.3:test
> {code}
> h2. Proposed fix
> Upgrade to 2.3.3
> h2. Sonatype Information
> *Issue*: CVE-2026-102495
> *Description from CVE*: Apache XmlSchema doesn't limit how deeply schema 
> imports and includes can be nested, so a malicious schema can make parsing 
> recurse until the stack overflows. This causes a denial of service. Users are 
> recommended to upgrade to version 2.3.3, which fixes this issue.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to