Uncontrolled Resource Consumption vulnerability in Apache Commons IO.
The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.
This issue affects Apache Commons IO: from 2.0 before 2.14.0.
Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade apache-commons-ioUpgrade apache-commons-io-javadoc | May 20, 2026 | May 20, 2026 |
| Debian | — | No solution existsUpgrade commons-io | May 15, 2025 | Oct 3, 2024 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 38792523 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 38793419 for version 14.1.1.0.0. | Jan 21, 2025 | Oct 3, 2024 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Jun 23, 2025 | Oct 3, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 3, 2024 |
| Ubuntu | — | Upgrade libcommons-io-java (Ubuntu Pro) | Apr 23, 2026 | Apr 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub