CVE-2025-46392 Details
Description
Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Apache Commons Configuration 1.x that allow excessive resource consumption when loading untrusted configurations or using unexpected usage patterns. The Apache Commons Configuration team does not intend to fix these issues in 1.x. Apache Commons Configuration 1.x is still safe to use in scenario's where you only load trusted configurations. Users that load untrusted configurations or give attackers control over usage patterns are recommended to upgrade to the 2.x version line, which fixes these issues. Apache Commons Configuration 2.x is not a drop-in replacement, but as it uses a separate Maven groupId and Java package namespace they can be loaded side-by-side, making it possible to do a gradual migration.
A vulnerability allowing uncontrolled resource consumption has been identified in Apache Commons Configuration versions 1.x, prior to 2.0.0. This issue arises when loading untrusted configurations or through unexpected usage patterns, leading to excessive resource use. While version 1.x is safe for trusted configurations, users who load untrusted data or allow attackers to manipulate usage patterns should upgrade to version 2.x, which addresses these concerns. Version 2.x is not a direct replacement for 1.x, but can be used alongside it for a gradual transition.
Users are advised to upgrade to Apache Commons Configuration version 2.x. Instructions for migration can be found in the Apache Commons Configuration documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.apache.org/thread/y1pl0mn3opz6kwkm873zshjdxq3dwq5s | [email protected] | Mailing ListVendor Advisory |
| https://www.cve.org/CVERecord?id=CVE-2024-29131 | [email protected] | Not Applicable |
| https://www.cve.org/CVERecord?id=CVE-2024-29133 | [email protected] | Not Applicable |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache commons configuration | >= 1.0, < 2.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 16, 2025 | Initial Analysis | [email protected] |
| May 13, 2025 | CVE Modified | CISA-ADP |
| May 9, 2025 | New CVE Received | [email protected] |