## This update for apache-commons-configuration2, apache-commons-text fixes the following issues * CVE-2026-45205: uncontrolled recursion leads to `StackOverflowError` when processing specially crafted configuration files (bsc#1265299). Changes for apache-commons-configuration2: * Upgrade to version 2.15.0: * Disable include schemes http[s] by default, see AbstractFileLocationStrategy * Detect and avoid processing cycles in YAML input (YAMLConfiguration) (bsc#1265299, CVE-2026-45205) * Extend scheme validation to inner schemes of jar: URLs * Add XMLConfiguration.read(Element) * Add ConfigurationException.ConfigurationException(String, Object...) * Add ConfigurationException.ConfigurationException(Throwable, String, Object...)
* bsc#1265299
Cross-
* CVE-2026-45205
CVSS scores:
* CVE-2026-45205 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-45205 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-45205 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products:
* Development Tools Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Real Time 15 SP7
Get the latest Linux and open source security news straight to your inbox.