Apache Commons Configuration Uncontrolled Resource Consumption Vulnerability

Vulnerability

A vulnerability allowing uncontrolled resource consumption has been identified in Apache Commons Configuration versions 1.x, prior to 2.0.0. This issue arises when loading untrusted configurations or through unexpected usage patterns, leading to excessive resource use. While version 1.x is safe for trusted configurations, users who load untrusted data or allow attackers to manipulate usage patterns should upgrade to version 2.x, which addresses these concerns. Version 2.x is not a direct replacement for 1.x, but can be used alongside it for a gradual transition.

Impact

Exploitation of this vulnerability can lead to a StackOverflowError, causing a denial of service by exhausting the application's stack space.

Remediation

Users are advised to upgrade to Apache Commons Configuration version 2.x. Instructions for migration can be found in the Apache Commons Configuration documentation.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
2.5
exploitability
4.7
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.