Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-45205

Опубликовано: 14 мая 2026
Источник: debian
EPSS Низкий

Описание

Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Commons: from 2.2 before 2.15.0. Users are recommended to upgrade to version 2.15.0, which fixes the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
commons-configuration2unfixedpackage
commons-configuration2no-dsatrixiepackage
commons-configuration2no-dsabookwormpackage
commons-configuration2postponedbullseyepackage
commons-configurationnot-affectedpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2026/05/14/5

  • https://github.com/apache/commons-configuration/pull/634

  • https://github.com/apache/commons-configuration/commit/b51f6bf26e774f3416fdf782a5e1edf33f32ba82 (commons-configuration-2.15.0-RC1)

EPSS

Процентиль: 38%
0.00469
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Commons: from 2.2 before 2.15.0. Users are recommended to upgrade to version 2.15.0, which fixes the issue.

CVSS3: 7.5
redhat
3 месяца назад

Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Commons: from 2.2 before 2.15.0. Users are recommended to upgrade to version 2.15.0, which fixes the issue.

CVSS3: 5.3
nvd
3 месяца назад

Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Commons: from 2.2 before 2.15.0. Users are recommended to upgrade to version 2.15.0, which fixes the issue.

suse-cvrf
около 1 месяца назад

Security update for apache-commons-configuration2, apache-commons-text

CVSS3: 5.3
github
3 месяца назад

Apache Commons Configuration: StackOverflowError for YAML input with cycles

EPSS

Процентиль: 38%
0.00469
Низкий