MEDIUM5.3
GHSA-337m-mw94-2v6g
Apache Commons Configuration: StackOverflowError for YAML input with cycles
Quick fix
GHSA-337m-mw94-2v6g — org.apache.commons:commons-configuration2: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.15.0</version> for org.apache.commons:commons-configuration2Details
Uncontrolled Recursion vulnerability in Apache Commons.
When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Commons: from 2.2 before 2.15.0.
Users are recommended to upgrade to version 2.15.0, which fixes the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.apache.commons:commons-configuration2
Introduced in:
2.2Fixed in: 2.15.0Fix
# pom.xml: bump <version>2.15.0</version> for org.apache.commons:commons-configuration2References
- https://nvd.nist.gov/vuln/detail/CVE-2026-45205[ADVISORY]
- https://github.com/apache/commons-configuration/pull/634[WEB]
- https://github.com/apache/commons-configuration[PACKAGE]
- https://lists.apache.org/thread/q3q3j10ohcqhs6o0rg1v7kz6kk27vtkk[WEB]
- http://www.openwall.com/lists/oss-security/2026/05/14/5[WEB]