Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3.3, which fixes this issue.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Apache XmlSchema versions prior to 2.3.3 fail to enforce depth limits on nested schema imports and includes, allowing attackers to craft malicious XML schemas that trigger recursive parsing until stack exhaustion occurs. This vulnerability (CWE-674: Uncontrolled Recursion) impacts any application or service that parses untrusted XML schemas, particularly those handling SOAP web services, XML validation, or configuration file processing. Organizations running vulnerable versions face availability risks, as a single malicious schema submission can crash parsing operations and disrupt dependent services without requiring authentication or elevated privileges.
While this CVE maps to CWE-674 rather than specific MITRE ATT&CK techniques, Casky's AI-powered analysis would identify the attack pattern as a resource exhaustion mechanism aligned with techniques like T1499 (Endpoint Denial of Service). Practitioners using Casky would observe findings flagging recursive XML processing patterns, stack depth anomalies during schema validation, and sudden resource spikes correlating with schema import operations. The platform's extended reasoning capabilities would correlate schema nesting depth metrics against safe thresholds, helping security teams distinguish between legitimate complex schemas and malicious recursive structures before they reach production systems. Upgrading to version 2.3.3 or later immediately mitigates this risk by implementing depth validation.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-102495. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation