[Git][security-tracker-team/security-tracker][master] Add CVE-2026-45205/commons-configuration2

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu May 14 20:34:07 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e71da7b4 by Salvatore Bonaccorso at 2026-05-14T21:33:39+02:00
Add CVE-2026-45205/commons-configuration2

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -50,7 +50,10 @@ CVE-2026-45375 (SiYuan is an open-source personal knowledge management system. P
 CVE-2026-45371 (SiYuan is an open-source personal knowledge management system. Prior t ...)
 	TODO: check
 CVE-2026-45205 (Uncontrolled Recursion vulnerability in Apache Commons.  When processi ...)
-	TODO: check
+	- commons-configuration2 <unfixed>
+	NOTE: https://www.openwall.com/lists/oss-security/2026/05/14/5
+	NOTE: https://github.com/apache/commons-configuration/pull/634
+	NOTE: https://github.com/apache/commons-configuration/commit/b51f6bf26e774f3416fdf782a5e1edf33f32ba82 (commons-configuration-2.15.0-RC1)
 CVE-2026-45148 (SiYuan is an open-source personal knowledge management system. Prior t ...)
 	TODO: check
 CVE-2026-45147 (SiYuan is an open-source personal knowledge management system. Prior t ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e71da7b4dd5d915841b767c07c870e17421173bb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e71da7b4dd5d915841b767c07c870e17421173bb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260514/7011d40f/attachment.htm>


More information about the debian-security-tracker-commits mailing list