{"id":"SUSE-SU-2026:2642-1","summary":"Security update for apache-commons-configuration2, apache-commons-text","details":"This update for apache-commons-configuration2, apache-commons-text fixes the following issues\n\n- CVE-2026-45205: uncontrolled recursion leads to `StackOverflowError` when processing specially crafted configuration\n  files (bsc#1265299).\n\nChanges for apache-commons-configuration2:\n  \n- Upgrade to version 2.15.0:\n + Disable include schemes http[s] by default, see\n AbstractFileLocationStrategy\n + Detect and avoid processing cycles in YAML input\n (YAMLConfiguration) (bsc#1265299, CVE-2026-45205)\n + Extend scheme validation to inner schemes of jar: URLs\n + Add XMLConfiguration.read(Element)\n + Add ConfigurationException.ConfigurationException(String,\n Object...)\n + Add ConfigurationException.ConfigurationException(Throwable,\n String, Object...)\n + Add ConversionException.ConversionException(String, Object...)\n + Add ConversionException.ConversionException(Throwable, String,\n + Add ConfigurationRuntimeException\n .ConfigurationRuntimeException(Throwable, String, Object...)\n * Fixed Bugs\n + Fix Apache RAT plugin console warnings\n + Migrate from deprecated APIs\n + Add org.apache.commons.configuration2.ImmutableConfiguration\n .entrySet()\n .forEach(BiConsumer\u003cString, Object\u003e)\n + Add VEX entry for CVE-2025-48924\n + Shared primitive variable 'throwExceptionOnMissing' in one\n thread may not yield the value of the most recent write from\n another thread [org.apache.commons.configuration2\n .AbstractConfiguration] At AbstractConfiguration.java:\n [line 1493] AT_STALE_THREAD_WRITE_OF_PRIMITIVE\n + Shared primitive variable 'forceSingleLine' in one thread may\n not yield the value of the most recent write from another\n thread [org.apache.commons.configuration2\n .PropertiesConfigurationLayout]\n At PropertiesConfigurationLayout.java:[line 821]\n AT_STALE_THREAD_WRITE_OF_PRIMITIVE\n + CONFIGURATION-849: Fix undoubling of strings\n + CONFIGURATION-852: Mark the package jakarta.servlet.* import\n as optional in OSGi\n + Fix build [WARNING] Parameter 'forkMode' is unknown for plugin\n 'maven-surefire-plugin:3.5.3:test (default-test)'\n * New features:\n + Add PrefixedKeysIterator.toString() to package-private\n PrefixedKeysIterator\n + CONFIGURATION-836: New web configurations using the\n jakarta.servlet namespace are now available\n + CONFIGURATION-836: Add org.apache.commons.configuration2.web\n .JakartaServletConfiguration\n .JakartaServletContextConfiguration\n .JakartaServletFilterConfiguration\n .JakartaServletRequestConfiguration\n + Add org.apache.commons.configuration2\n .AbstractHierarchicalConfiguration.getKeysInternal(String,\n String)\n * Fixed Bugs:\n + PropertyConverter.to(Class, Object, DefaultConversionHandler)\n doesn't convert custom java.lang.Number subclasses\n + DefaultConversionHandler.convertValue(Object, Class,\n ConfigurationInterpolator) doesn't convert custom java.lang\n .Number subclasses\n + DefaultConversionHandler.to(Object, Class,\n + CONFIGURATION-848: SubsetConfiguration does not account for\n delimiters as it did in 2.9.0\n + CONFIGURATION-848: CompositeConfiguration does not account for\n + Describe the security model\n + De-emphasize the 1.x version line on the website\n + CONFIGURATION-851: HomeDirectoryLocationStrategy no longer\n resolves the user HOME directory correctly\n + CONFIGURATION-844: Add support for empty sections\n + Add ImmutableConfiguration.containsValue(Object)\n + Fail-fast with a NullPointerException if DataConfiguration\n .DataConfiguration(Configuration) is called with null\n + Fail-fast with a NullPointerException if\n XMLPropertiesConfiguration.XMLPropertiesConfiguration(Element)\n is called with null\n + Fail-fast with a NullPointerException if a SubsetConfiguration\n constructor is called with a null Configuration\n + CONFIGURATION-843: Methods should not be empty\n + Guard MapConfiguration against null maps\n AppletConfiguration(Applet) is called with null\n ServletConfiguration(Servlet) is called with null\n ServletConfiguration(ServletConfig) is called with null\n ServletContextConfiguration(Servlet) is called with null\n ServletContextConfiguration(ServletContext) is called with null\n ServletFilterConfiguration(FilterConfig) is called with null\n ServletRequestConfiguration(ServletRequest) is called with\n null\n + Deprecate DatabaseConfiguration.getDatasource() in favor of\n getDataSource()\n + Fix PMD DynamicCombinedConfiguration in\n AbstractImmutableNodeHandler\n AbstractListDelimiterHandler\n DefaultPrefixLookupsHolder\n DynamicCombinedConfiguration\n PropertiesConfiguration\n + CONFIGURATION-846: Restore previous behavior allowing Spring\n to inject multiple values\n + CONFIGURATION-847: Property with an empty string value was not\n processed\n\nChanges for apache-commons-text:\n\n- Upgrade to version 1.15.0\n * New features\n + Add experimental CycloneDX VEX file\n + TEXT-235: Add Damerau-Levenshtein distance\n + Add unit tests to increase coverage\n + Add new test for CharSequenceTranslator#with()\n + Add tests and assertions to org.apache.commons.text.similarity\n to get to 100% code coverage\n * Fixed Bugs\n + Fix exception message typo in XmlStringLookup\n .XmlStringLookup(Map, Path...)\n + TEXT-236: Inserting at the end of a TextStringBuilder throws\n a StringIndexOutOfBoundsException\n + Fix TextStringBuilderTest.testAppendToCharBuffer() to use\n proper argument type\n + Fix Apache RAT plugin console warnings\n + Fix site XML to use version 2.0.0 XML schema\n + Removed unreachable threshold verification code in\n src/main/java/org/apache/commons/text/similarity\n + Enable secure processing for the XML parser in XmlStringLookup\n in case the underlying JAXP implementation doesn't\n + Interface StringLookup now extends UnaryOperator\u003cString\u003e\n + Interface TextRandomProvider extends IntUnaryOperator\n + Add RandomStringGenerator.Builder\n .usingRandom(IntUnaryOperator)\n + Add PMD check to default Maven goal\n + Add org.apache.commons.text.RandomStringGenerator.Builder\n .setAccumulate(boolean)\n + Fix PMD UnnecessaryFullyQualifiedName in StringLookupFactory\n + Fix PMD UnnecessaryFullyQualifiedName in\n DefaultStringLookupsHolder\n PropertiesStringLookup\n JavaPlatformStringLookup\n + Fix PMD UnnecessaryFullyQualifiedName in StringSubstitutor\n + Fix PMD UnnecessaryFullyQualifiedName in StrSubstitutor\n + Fix PMD UnnecessaryFullyQualifiedName in AlphabetConverter\n + Fix PMD AvoidBranchingStatementAsLastInLoop in\n TextStringBuilder\n + Fix PMD AvoidBranchingStatementAsLastInLoop in StrBuilder\n + org.apache.commons.text.translate.LookupTranslator\n .LookupTranslator(Map CharSequence\u003e) now throws\n NullPointerException instead of\n java.security.InvalidParameterException\n + Remove -nouses directive from maven-bundle-plugin. OSGi\n package imports now state 'uses' definitions for package\n imports, this doesn't affect JPMS\n (from org.apache.commons:commons-parent:80)\n + Deprecate EntityArrays.EntityArrays()\n + StringLookupFactory.DefaultStringLookupsHolder\n .createDefaultStringLookups() maps DefaultStringLookup\n .LOCAL_HOST twice instead of once for LOCAL_HOST and\n LOOPBACK_ADDRESS\n + Add StringLookupFactory.loopbackAddressStringLookup()\n + Add StringLookupFactory.KEY_LOOPBACK_ADDRESS\n + Add DefaultStringLookup.LOOPBACK_ADDRESS\n + Add richer inputs in package org.apache.commons.text\n .similarity with SimilarityInput\n + Add HammingDistance.apply(SimilarityInput, SimilarityInput)\n + Add JaccardDistance.apply(SimilarityInput, SimilarityInput)\n + Add JaccardSimilarity.apply(SimilarityInput, SimilarityInput)\n + Add JaroWinklerDistance.apply(SimilarityInput,\n SimilarityInput)\n + Add JaroWinklerSimilarity.apply(SimilarityInput,\n + Add LevenshteinDetailedDistance.apply(SimilarityInput,\n + Add LevenshteinDistance.apply(SimilarityInput,\n + Fix build on Java 22\n + Fix build on Java 23-ea\n + Make package-private constructor private:\n StrLookup.MapStrLookup.MapStrLookup(Map)\n + Make package-private constructor private: StrLookup\n .SystemPropertiesStrLookup.SystemPropertiesStrLookup()\n + Make package-private class private and final: MapStrLookup\n + Make package-private class private: StrMatcher.CharMatcher\n + Make package-private class private: StrMatcher.CharSetMatcher\n + Make package-private class private: StrMatcher.NoMatcher\n + Make package-private class private: StrMatcher.StringMatcher\n + Make package-private class private: StrMatcher.TrimMatcher\n + Make package-private class private and final:\n IntersectionSimilarity.BagCount\n IntersectionSimilarity.TinyCount\n + Deprecate LevenshteinDistance.LevenshteinDistance() in favor\n of LevenshteinDistance.getDefaultInstance()\n + Deprecate LevenshteinDetailedDistance\n .LevenshteinDetailedDistance() in favor of\n LevenshteinDetailedDistance.getDefaultInstance()\n + TEXT-234: Improve StrBuilder documentation for new line text\n + TEXT-234: Improve TextStringBuilder documentation for new line\n text\n + TEXT-233: Required OSGi Import-Package version numbers in\n MANIFEST.MF\n + Add StringLookupFactory.fileStringLookup(Path...) and\n deprecated fileStringLookup()\n + Add StringLookupFactory.propertiesStringLookup(Path...) and\n deprecated propertiesStringLookup()\n + Add StringLookupFactory.xmlStringLookup(Map, Path...) and\n deprecated xmlStringLookup() and xmlStringLookup(Map)\n + Add StringLookupFactory.builder() for fencing Path resolution\n of the file, properties and XML lookups\n + Add DoubleFormat.Builder.get() as Builder now implements\n Supplier\n + TEXT-232: WordUtils.containsAllWords?() may throw\n PatternSyntaxException\n + TEXT-175: Fix regression for determining whitespace in\n WordUtils\n + Deprecate Builder in favor of Supplier\n + TEXT-224: Set SecureProcessing feature in XmlStringLookup by\n default\n + TEXT-224: Add StringLookupFactory.xmlStringLookup(Map\u003cString,\n Boolean\u003e...)\n + Add @FunctionalInterface to FormatFactory\n + Add RandomStringGenerator.builder()\n + TEXT-229: Add XmlEncoderStringLookup/XmlDecoderStringLookup\n + Add StringSubstitutor.toString()\n + TEXT-219: Fix StringTokenizer.getTokenList to return an\n independent modifiable list\n + Fix Javadoc for StringEscapeUtils.escapeHtml4\n + TextStringBuidler#hashCode() allocates a String on each call\n + TEXT-221: Fix Bundle-SymbolicName to use the package name\n org.apache.commons.text\n + Add and use a package-private singleton for RegexTokenizer\n + Add and use a package-private singleton for CosineSimilarity\n + Add and use a package-private singleton for\n LongestCommonSubsequence\n JaroWinklerSimilarity\n + Add and use a package-private singleton for JaccardSimilarity\n + [StepSecurity] ci: Harden GitHub Actions\n + Improve AlphabetConverter Javadoc\n + Fix exception message in IntersectionResult to make\n set-theoretic sense\n + Add null-check in RandomStringGenerator#Builder#selectFrom()\n to avoid NullPointerException\n + Add null-check in RandomStringGenerator#Builder#withinRange()\n + TEXT-228: Fix TextStringBuilder to over-allocate when ensuring\n capacity\n + Constructor for ResourceBundleStringLookup should be private\n instead of package-private\n + Constructor for UrlDecoderStringLookup should be private\n + Constructor for UrlEncoderStringLookup should be private\n + TEXT-230: Javadoc of org.apache.commons.text.lookup\n .DefaultStringLookup.XML is incorrect\n + Update DoubleFormat to state it is based on Double.toString\n","modified":"2026-06-27T08:45:05.265944280Z","published":"2026-06-26T07:59:44Z","related":["CVE-2026-45205"],"upstream":["CVE-2026-45205"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262642-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265299"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45205"}],"affected":[{"package":{"name":"apache-commons-configuration2","ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15 SP7","purl":"pkg:rpm/suse/apache-commons-configuration2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.15.0-150200.5.11.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-configuration2":"2.15.0-150200.5.11.1","apache-commons-text":"1.15.0-150200.5.14.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-text","ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15 SP7","purl":"pkg:rpm/suse/apache-commons-text&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.15.0-150200.5.14.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-text":"1.15.0-150200.5.14.1","apache-commons-configuration2":"2.15.0-150200.5.11.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-configuration2","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/apache-commons-configuration2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.15.0-150200.5.11.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-configuration2":"2.15.0-150200.5.11.1","apache-commons-text":"1.15.0-150200.5.14.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-text","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/apache-commons-text&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.15.0-150200.5.14.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-text":"1.15.0-150200.5.14.1","apache-commons-configuration2":"2.15.0-150200.5.11.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-configuration2","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/apache-commons-configuration2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.15.0-150200.5.11.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-configuration2":"2.15.0-150200.5.11.1","apache-commons-text":"1.15.0-150200.5.14.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-text","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/apache-commons-text&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.15.0-150200.5.14.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-configuration2":"2.15.0-150200.5.11.1","apache-commons-text":"1.15.0-150200.5.14.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-configuration2","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/apache-commons-configuration2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.15.0-150200.5.11.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-configuration2":"2.15.0-150200.5.11.1","apache-commons-text":"1.15.0-150200.5.14.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-text","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/apache-commons-text&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.15.0-150200.5.14.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-configuration2":"2.15.0-150200.5.11.1","apache-commons-text":"1.15.0-150200.5.14.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-configuration2","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/apache-commons-configuration2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.15.0-150200.5.11.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-configuration2":"2.15.0-150200.5.11.1","apache-commons-text":"1.15.0-150200.5.14.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-text","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/apache-commons-text&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.15.0-150200.5.14.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-text":"1.15.0-150200.5.14.1","apache-commons-configuration2":"2.15.0-150200.5.11.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-configuration2","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/apache-commons-configuration2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.15.0-150200.5.11.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-configuration2":"2.15.0-150200.5.11.1","apache-commons-text":"1.15.0-150200.5.14.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-text","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/apache-commons-text&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.15.0-150200.5.14.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-text":"1.15.0-150200.5.14.1","apache-commons-configuration2":"2.15.0-150200.5.11.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-configuration2","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/apache-commons-configuration2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.15.0-150200.5.11.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-configuration2":"2.15.0-150200.5.11.1","apache-commons-text":"1.15.0-150200.5.14.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-text","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/apache-commons-text&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.15.0-150200.5.14.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-text":"1.15.0-150200.5.14.1","apache-commons-configuration2":"2.15.0-150200.5.11.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-configuration2","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/apache-commons-configuration2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.15.0-150200.5.11.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-configuration2":"2.15.0-150200.5.11.1","apache-commons-text":"1.15.0-150200.5.14.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-text","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/apache-commons-text&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.15.0-150200.5.14.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-configuration2":"2.15.0-150200.5.11.1","apache-commons-text":"1.15.0-150200.5.14.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-configuration2","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/apache-commons-configuration2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.15.0-150200.5.11.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-text":"1.15.0-150200.5.14.1","apache-commons-configuration2":"2.15.0-150200.5.11.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-text","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/apache-commons-text&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.15.0-150200.5.14.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-configuration2":"2.15.0-150200.5.11.1","apache-commons-text":"1.15.0-150200.5.14.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-configuration2","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/apache-commons-configuration2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.15.0-150200.5.11.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-configuration2":"2.15.0-150200.5.11.1","apache-commons-text":"1.15.0-150200.5.14.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-text","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/apache-commons-text&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.15.0-150200.5.14.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-configuration2":"2.15.0-150200.5.11.1","apache-commons-text":"1.15.0-150200.5.14.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-configuration2","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/apache-commons-configuration2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.15.0-150200.5.11.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-configuration2":"2.15.0-150200.5.11.1","apache-commons-text":"1.15.0-150200.5.14.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}},{"package":{"name":"apache-commons-text","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/apache-commons-text&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.15.0-150200.5.14.1"}]}],"ecosystem_specific":{"binaries":[{"apache-commons-text":"1.15.0-150200.5.14.1","apache-commons-configuration2":"2.15.0-150200.5.11.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2642-1.json"}}],"schema_version":"1.7.5"}