suse · CVE-2026-45205

Quick triage

Priority: high Published: 2026-05-14 23:16:09 UTC Updated: 2026-05-14 23:16:09 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2026-45205 severity important: SUSE including 1 source package names (apache-commons-configuration), 9 product×package rows across 9 product lines (SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS, SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS, … (9 product lines)): Known Not Affected 9.

Description:

Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Commons: from 2.2 before 2.15.0. Users are recommended to upgrade to version 2.15.0, which fixes the issue.

cvelogic Threat Intelligence