Every CVE whose affected-product data names Apache Xmlschema, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (3)
CVE-2026-102495 — CVSS 7.5 (high): Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until…
CVE-2026-102496 — CVSS 7.5 (high): Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make…
CVE-2026-102497 — CVSS 7.5 (high): The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute…