The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.
This issue affects Apache Commons IO: from 2.0 before 2.14.0.
Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-78wr-2p64-hpwj | Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader |
Ubuntu USN |
USN-8191-1 | Apache Commons IO vulnerability |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 31 Jan 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 14 Nov 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat amq Streams |
|
| CPEs | cpe:/a:redhat:amq_streams:2 | |
| Vendors & Products |
Redhat
Redhat amq Streams |
Fri, 04 Oct 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 03 Oct 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Oct 2024 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue. | |
| Title | Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader | |
| Weaknesses | CWE-400 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-01-31T15:02:47.229Z
Reserved: 2024-09-26T16:12:46.116Z
Link: CVE-2024-47554
Updated: 2025-01-31T15:02:47.229Z
Status : Analyzed
Published: 2024-10-03T12:15:02.613
Modified: 2025-07-10T21:10:32.113
Link: CVE-2024-47554
OpenCVE Enrichment
No data.
Github GHSA
Ubuntu USN