Skip to content

[maven-4.0.x] DefaultModelBuilder: getEnhancedProperties StackOverflow recursion #12598

Description

@elharo

DefaultModelBuilder: getEnhancedProperties StackOverflow recursion

Found in: maven-4.0.x branch
File: impl/maven-impl/src/main/java/org/apache/maven/impl/model/DefaultModelBuilder.java (lines 728-748)
Severity: Medium

Description

getEnhancedProperties calls derive(Sources.buildSource(rootModelPath)).readFileModel(activeModelReads) recursively. The activeModelReads guard only checks normalized path, but if the root model's project directory and rootDirectory differ in a way that causes locateExistingPom to return a path whose normalized form is NOT in activeModelReads but still eventually leads back to the same model, a StackOverflowError can occur.

The comment at lines 736-737 explicitly acknowledges this: "to prevent StackOverflowError when a project has an internal parent in a subdirectory with CI-friendly ${revision} and a .mvn/ root marker (GH-12301)".

This can crash Maven entirely in complex multi-module projects with .mvn/ root markers and CI-friendly versions.

Activity

  1. added this to the 4.0.0-rc-7 milestone on Aug 23, 2026
  2. added 2 commits that reference this issue on Aug 24, 2026
  3. added a commit that references this issue on Aug 28, 2026
    9062a70
  4. added a commit that references this issue on Aug 28, 2026
    ff24de2
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingmvn4

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions