🛡️ SUSE-SU-2026:2642-1 — apache-commons-configuration2 (CVE-2026-45205 +1 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for apache-commons-configuration2, apache-commons-text

This update for apache-commons-configuration2, apache-commons-text fixes the following issues

  • CVE-2026-45205: uncontrolled recursion leads to StackOverflowError when processing specially crafted configuration

files (bsc#1265299).

Changes for apache-commons-configuration2:

  • Upgrade to version 2.15.0:

+ Disable include schemes http[s] by default, see

AbstractFileLocationStrategy

+ Detect and avoid processing cycles in YAML input

(YAMLConfiguration) (bsc#1265299, CVE-2026-45205)

+ Extend scheme validation to inner schemes of jar: URLs

+ Add XMLConfiguration.read(Element)

+ Add ConfigurationException.ConfigurationException(String,

Object...)

+ Add ConfigurationException.ConfigurationException(Throwable,

String, Object...)

+ Add ConversionException.ConversionException(String, Object...)

+ Add ConversionException.ConversionException(Throwable, String,

+ Add ConfigurationRuntimeException

.ConfigurationRuntimeException(Throwable, String, Object...)

  • Fixed Bugs

+ Fix Apache RAT plugin console warnings

+ Migrate from deprecated APIs

+ Add org.apache.commons.configuration2.ImmutableConfiguration

.entrySet()

.forEach(BiConsumer<String, Object>)

+ Add VEX entry for CVE-2025-48924

+ Shared primitive variable 'throwExceptionOnMissing' in one

thread may not yield the value of the most recent write from

another thread [org.apache.commons.configuration2

.AbstractConfiguration] At AbstractConfiguration.java:

[line 1493] AT_STALE_THREAD_WRITE_OF_PRIMITIVE

+ Shared primitive variable 'forceSingleLine' in one thread may

not yield the value of the most recent write from another

thread [org.apache.commons.configuration2

.PropertiesConfigurationLayout]

At PropertiesConfigurationLayout.java:[line 821]

AT_STALE_THREAD_WRITE_OF_PRIMITIVE

+ CONFIGURATION-849: Fix undoubling of strings

+ CONFIGURATION-852: Mark the package jakarta.servlet.* import

as optional in OSGi

+ Fix build [WARNING] Parameter 'forkMode' is unknown for plugin

'maven-surefire-plugin:3.5.3:test (default-test)'

  • New features:

+ Add PrefixedKeysIterator.toString() to package-private

PrefixedKeysIterator

+ CONFIGURATION-836: New web configurations using the

jakarta.servlet namespace are now available

+ CONFIGURATION-836: Add org.apache.commons.configuration2.web

.JakartaServletConfiguration

.JakartaServletContextConfiguration

.JakartaServletFilterConfiguration

.JakartaServletRequestConfiguration

+ Add org.apache.commons.configuration2

.AbstractHierarchicalConfiguration.getKeysInternal(String,

String)

  • Fixed Bugs:

+ PropertyConverter.to(Class, Object, DefaultConversionHandler)

doesn't convert custom java.lang.Number subclasses

+ DefaultConversionHandler.convertValue(Object, Class,

ConfigurationInterpolator) doesn't convert custom java.lang

.Number subclasses

+ DefaultConversionHandler.to(Object, Class,

+ CONFIGURATION-848: SubsetConfiguration does not account for

delimiters as it did in 2.9.0

+ CONFIGURATION-848: CompositeConfiguration does not account for

+ Describe the security model

+ De-emphasize the 1.x version line on the website

+ CONFIGURATION-851: HomeDirectoryLocationStrategy no longer

resolves the user HOME directory correctly

+ CONFIGURATION-844: Add support for empty sections

+ Add ImmutableConfiguration.containsValue(Object)

+ Fail-fast with a NullPointerException if DataConfiguration

.DataConfiguration(Configuration) is called with null

+ Fail-fast with a NullPointerException if

XMLPropertiesConfiguration.XMLPropertiesConfiguration(Element)

is called with null

+ Fail-fast with a NullPointerException if a SubsetConfiguration

constructor is called with a null Configuration

+ CONFIGURATION-843: Methods should not be empty

+ Guard MapConfiguration against null maps

AppletConfiguration(Applet) is called with null

ServletConfiguration(Servlet) is called with null

ServletConfiguration(ServletConfig) is called with null

ServletContextConfiguration(Servlet) is called with null

ServletContextConfiguration(ServletContext) is called with null

ServletFilterConfiguration(FilterConfig) is called with null

ServletRequestConfiguration(ServletRequest) is called with

null

+ Deprecate DatabaseConfiguration.getDatasource() in favor of

getDataSource()

+ Fix PMD DynamicCombinedConfiguration in

AbstractImmutableNodeHandler

AbstractListDelimiterHandler

DefaultPrefixLookupsHolder

DynamicCombinedConfiguration

PropertiesConfiguration

+ CONFIGURATION-846: Restore previous behavior allowing Spring

to inject multiple values

+ CONFIGURATION-847: Property with an empty string value was not

processed

Changes for apache-commons-text:

  • Upgrade to version 1.15.0
  • New features

+ Add experimental CycloneDX VEX file

+ TEXT-235: Add Damerau-Levenshtein distance

+ Add unit tests to increase coverage

+ Add new test for CharSequenceTranslator#with()

+ Add tests and assertions to org.apache.commons.text.similari

Affected software

SUSE-SU-2026:2642-1 is recorded against 2 packages.

  • apache-commons-configuration2 (fixed in 2.15.0-150200.5.11.1)
  • apache-commons-text (fixed in 1.15.0-150200.5.14.1)

Timeline and source

Published on 26 June 2026 and last revised on 27 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-06-26
Updated 2026-08-20
Modified 2026-06-27
Fix URL N/A

Affected Packages

Software From version Fixed in
apache-commons-configuration2 2.15.0-150200.5.11.1
apache-commons-text 1.15.0-150200.5.14.1

Free Vulnerability Check

Is your site affected by SUSE-SU-2026:2642-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2026:2642-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2026