{"id":"GHSA-j288-q9x7-2f5v","summary":"Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs","details":"Uncontrolled Recursion vulnerability in Apache Commons Lang.\n\nThis issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.\n\nThe methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop.\n\nUsers are recommended to upgrade to version 3.18.0, which fixes the issue.","aliases":["CVE-2025-48924"],"modified":"2026-02-04T03:18:02.851501Z","published":"2025-07-11T15:31:37Z","related":["CGA-j2mh-4wvr-f7fc"],"database_specific":{"cwe_ids":["CWE-674"],"github_reviewed_at":"2025-07-12T00:48:03Z","github_reviewed":true,"nvd_published_at":"2025-07-11T15:15:24Z","severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48924"},{"type":"WEB","url":"https://github.com/apache/commons-lang/commit/b424803abdb2bec818e4fbcb251ce031c22aca53"},{"type":"PACKAGE","url":"https://github.com/apache/commons-lang"},{"type":"WEB","url":"https://lists.apache.org/thread/bgv0lpswokgol11tloxnjfzdl7yrc1g1"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/08/msg00000.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/08/msg00026.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/09/msg00032.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/09/msg00036.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/07/11/1"}],"affected":[{"package":{"name":"org.apache.commons:commons-lang3","ecosystem":"Maven","purl":"pkg:maven/org.apache.commons/commons-lang3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0"},{"fixed":"3.18.0"}]}],"versions":["3.0","3.0.1","3.1","3.10","3.11","3.12.0","3.13.0","3.14.0","3.15.0","3.16.0","3.17.0","3.2","3.2.1","3.3","3.3.1","3.3.2","3.4","3.5","3.6","3.7","3.8","3.8.1","3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-j288-q9x7-2f5v/GHSA-j288-q9x7-2f5v.json"}},{"package":{"name":"commons-lang:commons-lang","ecosystem":"Maven","purl":"pkg:maven/commons-lang/commons-lang"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0"},{"last_affected":"2.6"}]}],"versions":["2.0","2.1","2.2","2.3","2.4","2.5","2.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-j288-q9x7-2f5v/GHSA-j288-q9x7-2f5v.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}