CVE-2025-46392

EUVD-2025-14160
Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x.

There are a number of issues in Apache Commons Configuration 1.x that allow excessive resource consumption when loading untrusted configurations or using unexpected usage patterns. The Apache Commons Configuration team does not intend to fix these issues in 1.x. Apache Commons Configuration 1.x is still safe to use in scenario's where you only load trusted configurations. 


Users that load untrusted configurations or give attackers control over usage patterns are recommended to upgrade to the 2.x version line, which fixes these issues. Apache Commons Configuration 2.x is not a drop-in replacement, but as it uses a separate Maven groupId and Java package namespace they can be loaded side-by-side, making it possible to do a gradual migration.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 78.55%
Affected Products (NVD)
VendorProductVersion
apachecommons_configuration
1.0 ≤
𝑥
< 2.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
commons-configuration
bookworm
ignored
bullseye
ignored
forky
vulnerable
sid
vulnerable
trixie
ignored
commons-configuration2
bookworm
2.8.0-2
fixed
bullseye
2.8.0-1~deb11u1
fixed
bullseye (security)
2.8.0-1~deb11u1
fixed
forky
2.11.0-3
fixed
sid
2.11.0-3
fixed
trixie
2.11.0-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
commons-configuration
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
ignored
plucky
ignored
questing
ignored
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage