CVE-2026-45205
published 2026-05-14CVE-2026-45205: Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.49%
38.6th percentile
Uncontrolled Recursion vulnerability in Apache Commons.
When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles.
This issue affects Apache Commons: from 2.2 before 2.15.0.
Users are recommended to upgrade to version 2.15.0, which fixes the issue.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | commons_configuration | >= 2.2 < 2.15.0 | 2.15.0 |
| apache_software_foundation | apache_commons_configuration | >= 2.2 < 2.15.0 | 2.15.0 |
| candlepinproject | candlepin | — | — |
| debian | commons-configuration2 | — | — |
| ocp-tools-4 | jenkins-rhel8 | — | — |
| ocp-tools-4 | jenkins-rhel9 | — | — |
| qpid-cpp | qpid-cpp | — | — |
| rhoai | odh-spark-operator-rhel9 | — | — |
| rhoai | odh-th06-cpu-torch210-py312-rhel9 | — | — |
| rhoai | odh-th06-cpu-torch291-py312-rhel9 | — | — |
| rhoai | odh-th06-cuda130-torch210-py312-rhel9 | — | — |
| rhoai | odh-th06-cuda130-torch291-py312-rhel9 | — | — |
| rhoai | odh-th06-rocm64-torch291-py312-rhel9 | — | — |
| satellite_el8 | candlepin | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input
vendor_redhat·2026-05-14·CVSS 5.3
CVE-2026-45205 [MEDIUM] CWE-606 commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input
commons-configuration: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input
Uncontrolled Recursion vulnerability in Apache Commons.
When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles.
This issue affects Apache Commons: from 2.2 before 2.15.0.
Users are recommended to upgrade to version 2.15.0, which fixes the issue.
A flaw was found in Apache Commons Configuration. When processing an untrusted configuration file, a remote attacker could provide specially crafted YAML input with cycles. This could lead to an uncontrolled recursion, causing a StackOverflowError and resulting in a Denial of Service (DoS) for the affected system.
Statement: This Important flaw in Apac
GHSA
GHSA-337m-mw94-2v6g: Uncontrolled Recursion vulnerability in Apache Commons
ghsa_unreviewed·2026-05-14
CVE-2026-45205 [MEDIUM] CWE-674 GHSA-337m-mw94-2v6g: Uncontrolled Recursion vulnerability in Apache Commons
Uncontrolled Recursion vulnerability in Apache Commons.
When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles.
This issue affects Apache Commons: from 2.2 before 2.15.0.
Users are recommended to upgrade to version 2.15.0, which fixes the issue.
GHSA
Apache Commons Configuration: StackOverflowError for YAML input with cycles
ghsa·2026-05-14
CVE-2026-45205 [MEDIUM] CWE-674 Apache Commons Configuration: StackOverflowError for YAML input with cycles
Apache Commons Configuration: StackOverflowError for YAML input with cycles
Uncontrolled Recursion vulnerability in Apache Commons.
When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles.
This issue affects Apache Commons: from 2.2 before 2.15.0.
Users are recommended to upgrade to version 2.15.0, which fixes the issue.
VulDB
Apache Commons Configuration up to 2.14.x recursion
vuldb·2026-05-14·CVSS 5.3
CVE-2026-45205 [MEDIUM] Apache Commons Configuration up to 2.14.x recursion
A vulnerability categorized as problematic has been discovered in Apache Commons Configuration up to 2.14.x. The impacted element is an unknown function. Such manipulation leads to uncontrolled recursion.
This vulnerability is traded as CVE-2026-45205. Access to the local network is required for this attack to succeed. There is no exploit available.
It is advisable to upgrade the affected component.
No detection rules found.
No public exploits indexed.
2026-05-14
Published