What is CVE-2026-45205?
Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Commons: from 2.2 before 2.15.0. Users are recommended to upgrade to version 2.15.0, which fixes the issue.
Timeline
- 2026-05-14Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-17NVD record last updated
Affected product
Apache Commons Configuration
Remediation Steps
- Review ABB ICSA-26-120-06 advisory identifying affected Symphony Plus Engineering versions
- Evaluate PostScript processing vulnerabilities in your deployed configurations
- Apply vendor-recommended security updates to all affected installations
- Disable PostScript processing features if not essential to business operations
- Implement input validation and filtering for PostScript document handling
References
- https://github.com/apache/commons-configuration/pull/634
- https://lists.apache.org/thread/q3q3j10ohcqhs6o0rg1v7kz6kk27vtkk
- http://www.openwall.com/lists/oss-security/2026/05/14/5
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-120-06.json
- https://www.abb.com/en/products/software
- https://nvd.nist.gov/vuln/detail/CVE-2026-45205
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 1 of May 2026 (May 4 – 10)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.