Benjamin Marwell created CXF-9254:
-------------------------------------
Summary: Shipped xmlschema-core : 2.3.2 is vulnerable
(CVE-2026-102495)
Key: CXF-9254
URL: https://issues.apache.org/jira/browse/CXF-9254
Project: CXF
Issue Type: Bug
Components: Core
Affects Versions: 4.2.3
Reporter: Benjamin Marwell
h2. Issue description
Latest CXF Core has a dependency to xmlschema-core:
{code}
[INFO] +- org.apache.cxf:cxf-rt-rs-client:jar:4.2.3:runtime
[INFO] | +- org.apache.cxf:cxf-rt-transports-http:jar:4.2.3:runtime
[INFO] | +- org.apache.cxf:cxf-core:jar:4.2.3:runtime
[INFO] | | +- jakarta.annotation:jakarta.annotation-api:jar:2.1.1:runtime
[INFO] | | +- org.glassfish.jaxb:jaxb-runtime:jar:4.0.9:runtime
[INFO] | | | \- org.glassfish.jaxb:jaxb-core:jar:4.0.9:runtime
[INFO] | | | +- org.glassfish.jaxb:txw2:jar:4.0.9:runtime
[INFO] | | | \- com.sun.istack:istack-commons-runtime:jar:4.1.2:runtime
[INFO] | | +- com.fasterxml.woodstox:woodstox-core:jar:7.2.1:runtime
[INFO] | | | \- org.codehaus.woodstox:stax2-api:jar:4.3.0:runtime
[INFO] | | +- org.apache.ws.xmlschema:xmlschema-core:jar:2.3.2:runtime
[INFO] | | +- org.eclipse.angus:angus-activation:jar:2.0.3:runtime
[INFO] | | | \- jakarta.activation:jakarta.activation-api:jar:2.1.0:runtime
[INFO] | | \- jakarta.xml.bind:jakarta.xml.bind-api:jar:4.0.0:runtime
[INFO] | \- org.apache.cxf:cxf-rt-frontend-jaxrs:jar:4.2.3:test
[INFO] | \- org.apache.cxf:cxf-rt-security:jar:4.2.3:test
{code}
h2. Proposed fix
Upgrade to 2.3.3
h2. Sonatype Information
*Issue*: CVE-2026-102495
*Description from CVE*: Apache XmlSchema doesn't limit how deeply schema
imports and includes can be nested, so a malicious schema can make parsing
recurse until the stack overflows. This causes a denial of service. Users are
recommended to upgrade to version 2.3.3, which fixes this issue.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)