-
Notifications
You must be signed in to change notification settings - Fork 98
Open
Description
Hi Vincent,
Since your libray is using an old version of commons-lang, I leave you this warning about this CVE, just FYI.
Date: July 11, 2025
Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop. Users are recommended to upgrade to version 3.18.0, which fixes the issue.
Thanks for this awesome library.
Regards,
Joan.
Metadata
Metadata
Assignees
Labels
No labels