Back

HIGH

Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

Published Oct 3, 2024

Description

Uncontrolled Resource Consumption vulnerability in Apache Commons IO.

The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.

This issue affects Apache Commons IO: from 2.0 before 2.14.0.

Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Oct 3, 2024
Updated Jan 31, 2025
Reserved Sep 26, 2024
CISA Vulnrichment
Updated Oct 3, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 3, 2024
GHSA-78WR-2P64-HPWJ