🌐
GitHub
github.com › zeroturnaround › zt-exec › issues › 52
commons-lang 2.6 has vulnerabilities reported by Whitesource · Issue #52 · zeroturnaround/zt-exec
June 8, 2017 - It would be excellent if you could move to using commons-lang3 instead of commons-lang. Today WhiteSource static scanner started reporting two items in commons-lang 2.6 as blocker bugs. https://issues.apache.org/jira/browse/LANG-1049 htt...
Published   Oct 10, 2017
🌐
GitHub
github.com › hapifhir › hapi-fhir › issues › 7121
CVE-2025-48924 (Medium) detected in commons-lang-2.6.jar, commons-lang3-3.2.jar · Issue #7121 · hapifhir/hapi-fhir
May 19, 2025 - CVE-2025-48924 - Medium Severity Vulnerability Vulnerable Libraries - commons-lang-2.6.jar, commons-lang3-3.2.jar commons-lang-2.6.jar Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or ...
Published   Jul 13, 2025
🌐
GitHub
github.com › sassoftware › commons-lang
GitHub - sassoftware/commons-lang: Apache Commons Lang
Last Updated: November 10, 2025 Fix Version: commons-lang 2.6-CVE-2025-48924 Status: ✅ Fully Tested and Validated
Author   sassoftware
🌐
CVE Details
cvedetails.com › version › 637790 › Apache-Commons-Io-2.6.html
Apache Commons Io 2.6 security vulnerabilities, CVEs
Vulnerability statistics provide a quick overview for security vulnerabilities of Apache » Commons Io » version 2.6 .
🌐
Miggo
miggo.io › vulnerability-database › cve › CVE-2025-48924
CVE-2025-48924: Commons Lang ClassUtils DoS
Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.
🌐
GitHub
github.com › advisories › GHSA-j288-q9x7-2f5v
Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs · CVE-2025-48924 · GitHub Advisory Database · GitHub
Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.
🌐
IBM
ibm.com › support › pages › security-bulletin-security-vulnerability-apache-commons-lang-may-affect-ibm-business-automation-workflow-cve-2025-48924
Security Bulletin: Security vulnerability in Apache Commons Lang may affect IBM Business Automation Workflow - CVE-2025-48924
CVEID: CVE-2025-48924 DESCRIPTION: Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can ...
🌐
IBM
ibm.com › support › pages › security-bulletin-vulnerability-apache-commons-lang-may-affect-ibm-decision-optimization-ibm-cloud-pak-data-cve-2025-48924
Security Bulletin: A vulnerability in Apache Commons Lang may affect IBM Decision Optimization for IBM Cloud Pak for Data (CVE-2025-48924)
CVEID: CVE-2025-48924 DESCRIPTION: Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can ...
🌐
IBM
ibm.com › support › pages › security-bulletin-vulnerability-apache-commons-lang-cve-2025-48924-affects-ibm-powervm-novalink
Security Bulletin: Vulnerability in Apache Commons Lang (CVE-2025-48924) affects IBM PowerVM Novalink.
CVEID: CVE-2025-48924 DESCRIPTION: Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can ...
Find elsewhere
🌐
Apache JIRA
issues.apache.org › jira › browse › CASSANDRA-20849
[CASSANDRA-20849] commons-lang vulnerability: CVE-2025-48924 - ASF Jira
Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.
🌐
Snyk
security.snyk.io › snyk vulnerability database › maven
commons-lang:commons-lang vulnerabilities | Snyk
Published: 20 years ago Last updated: 15 years ago Latest version: 2.6 Latest non-vulnerable version: 1.0.1 ... Known vulnerabilities in the commons-lang:commons-lang package.
🌐
IBM
ibm.com › support › pages › security-bulletin-ibm-spss-analytic-server-affected-vulnerability-apache-commons-lang-cve-2025-48924
Security Bulletin: IBM SPSS Analytic Server is affected by a vulnerability in Apache Commons Lang (CVE-2025-48924).
CVEID: CVE-2025-48924 DESCRIPTION: Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can ...
🌐
Cybersecurity Help
cybersecurity-help.cz › vdb › apache_foundation › lang › 2.6
Known Vulnerabilities in Apache Commons Lang 2.6
Multiple vulnerabilities in Oracle Communications Offline Mediation Controller22 Oct, 2025 Medium Patched · Uncontrolled Recursion in Apache Commons Lang04 Aug, 2025 Medium Patched
🌐
GitHub
github.com › keycloak › keycloak › issues › 41184
CVE-2025-48924 - Uncontrolled Recursion vulnerability in Apache Commons Lang · Issue #41184 · keycloak/keycloak
April 27, 2025 - Package: org.apache.commons:commons-lang3 Installed Version: 3.17.0 Vulnerability CVE-2025-48924 Severity: MEDIUM Fixed Version: 3.18.0 Link: CVE-2025-48924 · This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.
Published   Jul 16, 2025
🌐
Broadcom
knowledge.broadcom.com › external › article › 407747 › cve202548924-apache-commons-lang-vulnera.html
CVE-2025-48924: Apache Commons Lang vulnerability in Siteminder Policy Server and AdminUI
August 19, 2025 - Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.
🌐
Apache Commons
commons.apache.org › proper › commons-lang › upgradeto2_6.html
2.6 Release Notes – Apache Commons Lang
Apache Commons, Apache Commons Lang, Apache, the Apache logo, and the Apache Commons project logos are trademarks of The Apache Software Foundation.
🌐
IBM
ibm.com › support › pages › security-bulletin-ibm-infosphere-information-server-affected-vulnerability-apache-commons-lang-cve-2025-48924
Security Bulletin: IBM InfoSphere Information Server is affected by a vulnerability in Apache Commons Lang (CVE-2025-48924)
CVEID: CVE-2025-48924 DESCRIPTION: Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can ...