Skip to content

chore(deps): update dependency commons-io:commons-io to v2.14.0 [security] - #339

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/commonsio.version
Open

chore(deps): update dependency commons-io:commons-io to v2.14.0 [security]#339
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/commonsio.version

Conversation

@renovate

@renovate renovate Bot commented Aug 1, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Change Age Confidence
commons-io:commons-io (source) 2.72.14.0 age confidence

Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

CVE-2024-47554 / GHSA-78wr-2p64-hpwj

More information

Details

Uncontrolled Resource Consumption vulnerability in Apache Commons IO.

The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.

This issue affects Apache Commons IO: from 2.0 before 2.14.0.

Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

Severity

  • CVSS Score: 8.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

CVE-2024-47554 / GHSA-78wr-2p64-hpwj

More information

Details

Uncontrolled Resource Consumption vulnerability in Apache Commons IO.

The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.

This issue affects Apache Commons IO: from 2.0 before 2.14.0.

Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

Severity

  • CVSS Score: 8.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner August 1, 2026 15:45
@renovate renovate Bot added dependencies Pull requests that update a dependency file renovate security labels Aug 1, 2026
@renovate
renovate Bot enabled auto-merge (squash) August 1, 2026 15:45
@bito-code-review

bito-code-review Bot commented Aug 1, 2026

Copy link
Copy Markdown

Review Skipped - Label Excluded

Bito didn't auto-review this change because the PR contains excluded label: renovate.
No action is needed if you didn't intend for the agent to review it. To trigger a review manually, type /review in a comment and save.

You can change this by removing the label from Filters → Exclude Labels setting here, or from the labels_excluded field in the .bito.yaml file (if repo-level configurations are enabled), or contact your workspace admin at michael.pearce@contentful.com.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file renovate security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants