VDB
GCVE-110-NCSC-2026-308
GCVE-110-NCSC-2026-308
Advisory PublishedCVSS 9.3/10
A denial of service vulnerability in Apache Xerces Java XML parser, affecting multiple Oracle products, causes infinite loops and resource exhaustion when processing crafted XML payloads, potentially leading to hangs or crashes requiring user interaction.
Weaknesses (CWE)
CWE-835Loop with Unreachable Exit Condition ('Infinite Loop')CWE-787Out-of-bounds Write
Risk Scores
CVSS 3.1
9.3/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Oracle | vers:unknown/* | — | — |
Aliases
CVE-2022-23437CVE-2024-9143CVE-2026-70953CVE-2026-70954CVE-2026-70955CVE-2026-70976CVE-2026-70977CVE-2026-70978CVE-2026-70979CVE-2026-70980CVE-2026-70981CVE-2026-70982CVE-2026-70983CVE-2026-70984CVE-2026-70985CVE-2026-70986CVE-2026-70987CVE-2026-70988CVE-2026-70989CVE-2026-70990CVE-2026-70991CVE-2026-70992CVE-2026-70993CVE-2026-70994CVE-2026-70995CVE-2026-70996CVE-2026-70997CVE-2026-70998CVE-2026-70999CVE-2026-71000CVE-2026-71001CVE-2026-71002CVE-2026-71003CVE-2026-71004CVE-2026-71005CVE-2026-71006CVE-2026-71007CVE-2026-71008CVE-2026-71009CVE-2026-71010CVE-2026-71011CVE-2026-71012CVE-2026-71014CVE-2026-71015CVE-2026-71016CVE-2026-71017CVE-2026-71018CVE-2026-71019CVE-2026-71020CVE-2026-71021CVE-2026-71022CVE-2026-71023CVE-2026-71024CVE-2026-71025CVE-2026-71026CVE-2026-71027CVE-2026-71028CVE-2026-71030CVE-2026-71031CVE-2026-71032CVE-2026-71033CVE-2026-71034CVE-2026-71035CVE-2026-71036CVE-2026-71037CVE-2026-71038
References
Browse GCVE Records
867 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.