CVE-2024-47554
published 2024-10-03CVE-2024-47554: Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU…
PriorityP420medium4.3CVSS 3.1
AVNACLPRNUIRSUCNINAL
EPSS
1.24%
66.0th percentile
Uncontrolled Resource Consumption vulnerability in Apache Commons IO.
The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.
This issue affects Apache Commons IO: from 2.0 before 2.14.0.
Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | commons_io | >= 2.0 < 2.14.0 | 2.14.0 |
| apache_software_foundation | apache_commons_io | >= 2.0 < 2.14.0 | 2.14.0 |
| debian | commons-io | < commons-io 2.16.0-1 (forky) | commons-io 2.16.0-1 (forky) |
| msrc | azl3_apache-commons-io_2.14.0-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_javapackages-bootstrap_1.14.0-3_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_apache-commons-io_2.14.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_javapackages-bootstrap_1.5.0-6_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| netapp | ontap_tools | — | — |
| netapp | ontap_tools | — | — |
| ubuntu | commons-io | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
osv4.3MEDIUM
vendor_oracle7.5MEDIUM
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache Commons IO vulnerability
vendor_ubuntu·2026-04-21
CVE-2024-47554 Apache Commons IO vulnerability
Title: Apache Commons IO vulnerability
Summary: Apache Commons IO could be made to crash if it received specially
crafted input.
It was discovered that Apache Commons IO's XmlStreamReader class
could excessively consume CPU resources under certain circumstances. An
attacker could possibly use this issue to cause Apache Commons IO
to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Console (Apache Commons IO) — CVE-2024-47554
vendor_oracle·2026-01-15·CVSS 4.3
CVE-2024-47554 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Console (Apache Commons IO) — CVE-2024-47554
Oracle Oracle Fusion Middleware Risk Matrix: Console (Apache Commons IO) vulnerability
CVE: CVE-2024-47554
CVSS: 4.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Oracle
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Apache Commons IO) — CVE-2024-47554
vendor_oracle·2025-10-15·CVSS 4.3
CVE-2024-47554 [MEDIUM] Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Apache Commons IO) — CVE-2024-47554
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Apache Commons IO) vulnerability
CVE: CVE-2024-47554
CVSS: 4.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Install (Apache Commons IO) — CVE-2024-47554
vendor_oracle·2025-07-15·CVSS 3.5
CVE-2024-47554 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Install (Apache Commons IO) — CVE-2024-47554
Oracle Oracle Communications Applications Risk Matrix: Install (Apache Commons IO) vulnerability
CVE: CVE-2024-47554
CVSS: 3.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Oracle
Oracle Oracle TimesTen In-Memory Database Risk Matrix: EM TimesTen plug-in (Apache Commons IO) — CVE-2024-47554
vendor_oracle·2025-04-15·CVSS 4.3
CVE-2024-47554 [MEDIUM] Oracle Oracle TimesTen In-Memory Database Risk Matrix: EM TimesTen plug-in (Apache Commons IO) — CVE-2024-47554
Oracle Oracle TimesTen In-Memory Database Risk Matrix: EM TimesTen plug-in (Apache Commons IO) vulnerability
CVE: CVE-2024-47554
CVSS: 4.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Solution Designer (Apache Commons IO) — CVE-2024-47554
vendor_oracle·2025-01-15·CVSS 7.5
CVE-2024-47554 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Solution Designer (Apache Commons IO) — CVE-2024-47554
Oracle Oracle Communications Applications Risk Matrix: Solution Designer (Apache Commons IO) vulnerability
CVE: CVE-2024-47554
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Microsoft
Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
vendor_msrc·2024-10-08·CVSS 4.3
CVE-2024-47554 [MEDIUM] CWE-400 Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Marin
Red Hat
apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReader
vendor_redhat·2024-10-03·CVSS 4.3
CVE-2024-47554 [MEDIUM] CWE-400 apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReader
apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReader
Uncontrolled Resource Consumption vulnerability in Apache Commons IO.
The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.
This issue affects Apache Commons IO: from 2.0 before 2.14.0.
Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.
A vulnerability was found in the Apache Commons IO component in the org.apache.commons.io.input.XmlStreamReader class. Excessive CPU resource consumption can lead to a denial of service when an untrusted input is processed.
Package: commons-io (A-MQ Clients 2) - Fix deferred
Package: commons-io (Cryostat 3) - Fix deferred
Package: commons-io (Cryostat
Debian
CVE-2024-47554: commons-io - Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.a...
vendor_debian·2024·CVSS 4.3
CVE-2024-47554 [MEDIUM] CVE-2024-47554: commons-io - Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.a...
Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.16.0-1)
sid: resolved (fixed in 2.16.0-1)
trixie: resolved (fixed in 2.16.0-1)
OSV
CVE-2024-47554: Uncontrolled Resource Consumption vulnerability in Apache Commons IO
osv·2024-10-03·CVSS 4.3
CVE-2024-47554 [MEDIUM] CVE-2024-47554: Uncontrolled Resource Consumption vulnerability in Apache Commons IO
Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.
OSV
Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
osv·2024-10-03
CVE-2024-47554 [HIGH] Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
Uncontrolled Resource Consumption vulnerability in Apache Commons IO.
The `org.apache.commons.io.input.XmlStreamReader` class may excessively consume CPU resources when processing maliciously crafted input.
This issue affects Apache Commons IO: from 2.0 before 2.14.0.
Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.
GHSA
Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
ghsa·2024-10-03
CVE-2024-47554 [HIGH] CWE-400 Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
Uncontrolled Resource Consumption vulnerability in Apache Commons IO.
The `org.apache.commons.io.input.XmlStreamReader` class may excessively consume CPU resources when processing maliciously crafted input.
This issue affects Apache Commons IO: from 2.0 before 2.14.0.
Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.
No detection rules found.
No public exploits indexed.
2024-10-03
Published