Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-45205

Опубликовано: 14 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Commons: from 2.2 before 2.15.0. Users are recommended to upgrade to version 2.15.0, which fixes the issue.

A flaw was found in Apache Commons Configuration. When processing an untrusted configuration file, a remote attacker could provide specially crafted YAML input with cycles. This could lead to an uncontrolled recursion, causing a StackOverflowError and resulting in a Denial of Service (DoS) for the affected system.

Отчет

This Important flaw in Apache Commons Configuration allows a remote attacker to trigger a denial of service by providing specially crafted YAML input containing cycles. This can lead to an uncontrolled recursion and a StackOverflowError, impacting the availability of systems that process untrusted YAML configuration files.

Меры по смягчению последствий

To mitigate this issue, restrict Apache Commons Configuration to process only trusted YAML configuration files. Implement strict input validation for any YAML content originating from untrusted sources to prevent the parsing of malformed input with cyclical references. This operational control reduces the exposure to denial of service attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and Servicesjenkins-2-pluginsAffected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Affected
Red Hat AMQ Broker 7commons-configuration2Affected
Red Hat AMQ Clientscommons-configuration2Affected
Red Hat build of Apache Camel for Spring Boot 4commons-configuration2Affected
Red Hat build of Apicurio Registry 3commons-configuration2Affected
Red Hat Data Grid 8commons-configurationNot affected
Red Hat Enterprise Linux 6qpid-cppAffected
Red Hat Enterprise Linux 6qpid-qmfAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-606
https://bugzilla.redhat.com/show_bug.cgi?id=2477425commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input

EPSS

Процентиль: 39%
0.00487
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Commons: from 2.2 before 2.15.0. Users are recommended to upgrade to version 2.15.0, which fixes the issue.

CVSS3: 5.3
nvd
3 месяца назад

Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Commons: from 2.2 before 2.15.0. Users are recommended to upgrade to version 2.15.0, which fixes the issue.

CVSS3: 5.3
debian
3 месяца назад

Uncontrolled Recursion vulnerability in Apache Commons. When processi ...

suse-cvrf
около 1 месяца назад

Security update for apache-commons-configuration2, apache-commons-text

CVSS3: 5.3
github
3 месяца назад

Apache Commons Configuration: StackOverflowError for YAML input with cycles

EPSS

Процентиль: 39%
0.00487
Низкий

7.5 High

CVSS3