VendorsApachecommons_configurationall versions
Vulnerabilities

Apache Software Foundation Commons Configuration

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2020-1953
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.
Published 2020-03-13 · Modified
10.0EPSS 0.068
CVE-2022-33980
Apache Commons Configuration insecure interpolation defaults
Published 2022-07-06 · Modified
9.8EPSS 0.456
CVE-2024-29131
Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()
Published 2024-03-21 · Analyzed
7.3EPSS 0.021
CVE-2025-46392
Apache Commons Configuration: Uncontrolled Resource Consumption when loading untrusted configurations in 1.x
Published 2025-05-09 · Analyzed
6.5EPSS 0.020
CVE-2024-29133
Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree
Published 2024-03-21 · Analyzed
5.4EPSS 0.017
CVE-2026-45205
Apache Commons Configuration: StackOverflowError for YAML input with cycles
Published 2026-05-14 · Analyzed
5.3EPSS 0.008