CVE-2025-48924Patch(apache / commons_lang)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache commons_lang systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • commons_lang

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 7 signals
  • Peaked 1d ago at 6 mentions (2026-03-11); latest day: 1
  • 7 total mentions across 2 days

Affected systems

Vendors
Products
commons_lang

Deep dive

Activity timeline7 mentions / 2d
02356Mentions · 2026-03-11: 6Mentions · 2026-03-21: 1Patch / Workaround · 2026-03-11: 6Patch / Workaround · 2026-03-21: 103-1103-21
Signal classification1 categories
Patch
7100.0%
Classification over time
DateTotalLabels
2026-03-116
Patch6
2026-03-211
Patch1
Full discourse7 posts
  • GCP Weekly@gcpweekly
    Patch

    2.2.79-rocky9, 2.2.79-ubuntu22, 2.2.79-ubuntu22-arm 2.3.26-debian12, 2.3.26-ml-ubuntu22, 2.3.26-rocky9, 2.3.26-ubuntu22, 2.3.26-ubuntu22-arm Fixed CVEs CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924, and CVE-2025-33042. Upgraded Dataproc Metastore Proxy to 2/3

    Post summary

    The notice announces that version upgrades have fixed multiple CVEs, confirming vendor patches were applied without any discussion of exploits or PoCs.

    1000032
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2022-40897 CVE-2025-47273 CVE-2025-48924 451224723, 451224123 Security fixes for apigee-fluent-bit 8/19

    Post summary

    The post lists several CVEs and states that security fixes for apigee-fluent‑bit were released on August 19, indicating patch availability.

    1000080
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-48924 CVE-2025-67735 471016560, 471015664, 471015120 Security fixes for apigee-hybrid-cassandra 7/19

    Post summary

    The message announces security fixes for apigee-hybrid-cassandra addressing a list of CVE identifiers.

    1000074
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-48924 CVE-2025-67735 471502495, 471501875, 471126425 Security fixes for apigee-mart-server 6/19

    Post summary

    The text announces that CVE-2025-48924, CVE-2025-67735, and several other issue IDs are addressed by security fixes in apigee-mart-server version 6/19.

    1000075
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    v1.15.2 Security Bug ID Description 471502899, 471173561 Security fixes for apigee-synchronizer. This addresses the following vulnerabilities: CVE-2025-48924 CVE-2025-67735 471502752, 471191392 Security fixes for apigee-runtime 5/19

    Post summary

    The note announces the release of security fixes for CVE-2025-48924, CVE-2025-67735, and related issues in Apigee Synchronizer and Runtime, indicating that patches have been applied.

    1000078
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    2.2.78-debian12, 2.2.78-rocky9, 2.2.78-ubuntu22, 2.2.78-ubuntu22-arm 2.3.25-debian12, 2.3.25-ml-ubuntu22, 2.3.25-rocky9, 2.3.25-ubuntu22, 2.3.25-ubuntu22-arm Fixed Fixed CVEs CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924 (partial), and CVE-2025-33042. 2/4

    Post summary

    Release notes announce that the listed CVEs have been fixed in the new package versions.

    1000098
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    2.1.110-ubuntu20-arm 2.2.78-debian12, 2.2.78-rocky9, 2.2.78-ubuntu22, 2.2.78-ubuntu22-arm 2.3.25-debian12, 2.3.25-ml-ubuntu22, 2.3.25-rocky9, 2.3.25-ubuntu22, 2.3.25-ubuntu22-arm Fixed Fixed CVEs CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924 (partial), and 2/4

    Post summary

    The text announces that specific software package versions have addressed and fixed the listed CVEs.

    1000088
    1.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecommons_lang---

Explore more