CVE-2018-17202: Apache Commons Imaging
High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.
Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to parse them, which could be used in a DoS attack. Note that Apache Sanselan (incubating) was renamed to Apache Commons Imaging.
Affected products
- Apache Commons Imaging: version 0.97 only
Published 2019-05-06. Last modified 2026-06-17.