Known vulnerabilities in Apache Commons Configuration
Vendor:
Apache Foundation
Software:
Apache Commons Configuration
Software CPE:
cpe:2.3:a:apache_foundation:configuration:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
6
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU145310 - Uncontrolled Recursion CVE-2026-45205 |
CWE-674 | Low | 2.15.0 | 25.08.2026 |
SB20260825101 SB20260825115 SB2026090313 and 1 more |
||
| #VU108843 - Resource exhaustion CVE-2025-46392 |
CWE-400 | Medium | 2.0 | 09.05.2025 |
SB2025050949 SB2025081124 SB2025091517 and 7 more |
||
| #VU87744 - Out-of-bounds write CVE-2024-29133 |
CWE-787 | High | 2.10.1 | 22.03.2024 |
SB2024032169 SB2024032283 SB20240417122 and 40 more |
||
| #VU87706 - Out-of-bounds write CVE-2024-29131 |
CWE-787 | High | 2.10.1 | 21.03.2024 |
SB2024032169 SB2024032283 SB20240417122 and 36 more |
||
| #VU64957 - Improper Control of Generation of Code ('Code Injection') CVE-2022-33980 |
CWE-94 | High | 2.8.0 | 06.07.2022 |
SB2022070645 SB2022072604 SB2022081517 and 31 more |
||
| #VU26146 - Improper Control of Generation of Code ('Code Injection') CVE-2020-1953 |
CWE-94 | Medium | 2.7 | 17.03.2020 |
SB2020031715 SB2020102941 SB2022090817 and 3 more |