🛡️ SUSE-SU-2026:2642-1 — apache-commons-configuration2 (CVE-2026-45205 +1 more)
Description
Security update for apache-commons-configuration2, apache-commons-text
This update for apache-commons-configuration2, apache-commons-text fixes the following issues
- CVE-2026-45205: uncontrolled recursion leads to
StackOverflowErrorwhen processing specially crafted configuration
files (bsc#1265299).
Changes for apache-commons-configuration2:
- Upgrade to version 2.15.0:
+ Disable include schemes http[s] by default, see
AbstractFileLocationStrategy
+ Detect and avoid processing cycles in YAML input
(YAMLConfiguration) (bsc#1265299, CVE-2026-45205)
+ Extend scheme validation to inner schemes of jar: URLs
+ Add XMLConfiguration.read(Element)
+ Add ConfigurationException.ConfigurationException(String,
Object...)
+ Add ConfigurationException.ConfigurationException(Throwable,
String, Object...)
+ Add ConversionException.ConversionException(String, Object...)
+ Add ConversionException.ConversionException(Throwable, String,
+ Add ConfigurationRuntimeException
.ConfigurationRuntimeException(Throwable, String, Object...)
- Fixed Bugs
+ Fix Apache RAT plugin console warnings
+ Migrate from deprecated APIs
+ Add org.apache.commons.configuration2.ImmutableConfiguration
.entrySet()
.forEach(BiConsumer<String, Object>)
+ Add VEX entry for CVE-2025-48924
+ Shared primitive variable 'throwExceptionOnMissing' in one
thread may not yield the value of the most recent write from
another thread [org.apache.commons.configuration2
.AbstractConfiguration] At AbstractConfiguration.java:
[line 1493] AT_STALE_THREAD_WRITE_OF_PRIMITIVE
+ Shared primitive variable 'forceSingleLine' in one thread may
not yield the value of the most recent write from another
thread [org.apache.commons.configuration2
.PropertiesConfigurationLayout]
At PropertiesConfigurationLayout.java:[line 821]
AT_STALE_THREAD_WRITE_OF_PRIMITIVE
+ CONFIGURATION-849: Fix undoubling of strings
+ CONFIGURATION-852: Mark the package jakarta.servlet.* import
as optional in OSGi
+ Fix build [WARNING] Parameter 'forkMode' is unknown for plugin
'maven-surefire-plugin:3.5.3:test (default-test)'
- New features:
+ Add PrefixedKeysIterator.toString() to package-private
PrefixedKeysIterator
+ CONFIGURATION-836: New web configurations using the
jakarta.servlet namespace are now available
+ CONFIGURATION-836: Add org.apache.commons.configuration2.web
.JakartaServletConfiguration
.JakartaServletContextConfiguration
.JakartaServletFilterConfiguration
.JakartaServletRequestConfiguration
+ Add org.apache.commons.configuration2
.AbstractHierarchicalConfiguration.getKeysInternal(String,
String)
- Fixed Bugs:
+ PropertyConverter.to(Class, Object, DefaultConversionHandler)
doesn't convert custom java.lang.Number subclasses
+ DefaultConversionHandler.convertValue(Object, Class,
ConfigurationInterpolator) doesn't convert custom java.lang
.Number subclasses
+ DefaultConversionHandler.to(Object, Class,
+ CONFIGURATION-848: SubsetConfiguration does not account for
delimiters as it did in 2.9.0
+ CONFIGURATION-848: CompositeConfiguration does not account for
+ Describe the security model
+ De-emphasize the 1.x version line on the website
+ CONFIGURATION-851: HomeDirectoryLocationStrategy no longer
resolves the user HOME directory correctly
+ CONFIGURATION-844: Add support for empty sections
+ Add ImmutableConfiguration.containsValue(Object)
+ Fail-fast with a NullPointerException if DataConfiguration
.DataConfiguration(Configuration) is called with null
+ Fail-fast with a NullPointerException if
XMLPropertiesConfiguration.XMLPropertiesConfiguration(Element)
is called with null
+ Fail-fast with a NullPointerException if a SubsetConfiguration
constructor is called with a null Configuration
+ CONFIGURATION-843: Methods should not be empty
+ Guard MapConfiguration against null maps
AppletConfiguration(Applet) is called with null
ServletConfiguration(Servlet) is called with null
ServletConfiguration(ServletConfig) is called with null
ServletContextConfiguration(Servlet) is called with null
ServletContextConfiguration(ServletContext) is called with null
ServletFilterConfiguration(FilterConfig) is called with null
ServletRequestConfiguration(ServletRequest) is called with
null
+ Deprecate DatabaseConfiguration.getDatasource() in favor of
getDataSource()
+ Fix PMD DynamicCombinedConfiguration in
AbstractImmutableNodeHandler
AbstractListDelimiterHandler
DefaultPrefixLookupsHolder
DynamicCombinedConfiguration
PropertiesConfiguration
+ CONFIGURATION-846: Restore previous behavior allowing Spring
to inject multiple values
+ CONFIGURATION-847: Property with an empty string value was not
processed
Changes for apache-commons-text:
- Upgrade to version 1.15.0
- New features
+ Add experimental CycloneDX VEX file
+ TEXT-235: Add Damerau-Levenshtein distance
+ Add unit tests to increase coverage
+ Add new test for CharSequenceTranslator#with()
+ Add tests and assertions to org.apache.commons.text.similari
Affected software
SUSE-SU-2026:2642-1 is recorded against 2 packages.
- apache-commons-configuration2 (fixed in 2.15.0-150200.5.11.1)
- apache-commons-text (fixed in 1.15.0-150200.5.14.1)
Timeline and source
Published on 26 June 2026 and last revised on 27 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.suse.com (Advisory)
bugzilla.suse.com (Report)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| apache-commons-configuration2 | — | 2.15.0-150200.5.11.1 |
| apache-commons-text | — | 1.15.0-150200.5.14.1 |
References
Similar Threats
- Unknown SUSE-SU-2026:21996-1
- Unknown openSUSE-SU-2026:10784-1
- Unknown openSUSE-SU-2024:13259-1
- Unknown openSUSE-SU-2024:13791-1
- Unknown SUSE-SU-2024:1365-1
Free Vulnerability Check
Is your site affected by SUSE-SU-2026:2642-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2026:2642-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.