Amazon Linux 2 — xerces-j2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide
🟡 Medium ⏱ 10–30 min Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read • Source: Amazon Linux advisory ALAS2-2024-2649 Related CVEs: CVE-2012-0881 CVE-2022-23437 Upstream summary: Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an […]