CVE-2026-45205
Uncontrolled Recursion vulnerability in Apache Commons.
When processing an untrusted configuration file, Commons Config
Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Commons: from 2.2 before 2.15.0.
Users are recommended to upgrade to version 2.15.0, which fixes the issue.
MEDIUM · CVSS 5.3
EPSS 0.00129
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules0
YARA rules0