CVE-2024-47554: Apache Commons Io

Medium severity, CVSS 4.3. EPSS: 1.3% chance of exploitation in the next 30 days.

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

Affected products

  • Apache Commons Io: from 2.0, before 2.14.0 (fixed in 2.14.0)
  • Netapp Active Iq Unified Manager: affected versions not specified
  • Netapp Bluexp: affected versions not specified
  • Netapp E-Series Santricity Unified Manager: affected versions not specified
  • Netapp E-Series Santricity Web Services Proxy: affected versions not specified
  • Netapp Ontap Tools: version 9 only; version 10 only
  • Netapp Santricity Storage Plugin: affected versions not specified
  • Netapp Snapcenter: affected versions not specified

Published 2024-10-03. Last modified 2026-06-17.