Uncontrolled Recursion vulnerability in Apache Commons Lang.
This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.
The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop.
Users are recommended to upgrade to version 3.18.0, which fixes the issue.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libcommons-lang-javaUpgrade libcommons-lang3-java | Jul 14, 2025 | Jul 11, 2025 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 38412437 for version 12.2.1.4.0. | Oct 22, 2025 | Oct 14, 2025 |
| Red Hat Jboss Eap | — | — | Jul 14, 2025 | Jul 11, 2025 |
| Redhat_linux | — | No solution exists | Jul 14, 2025 | Jul 11, 2025 |
| Suse | — | Upgrade apache-commons-lang-javadocUpgrade apache-commons-lang3-javadocUpgrade apache-commons-lang3Upgrade apache-commons-lang | Dec 5, 2025 | Aug 13, 2025 |
| Ubuntu | — | Upgrade libcommons-lang-javaUpgrade libcommons-lang-java (Ubuntu Pro)Upgrade libcommons-lang3-java (Ubuntu Pro)Upgrade libcommons-lang3-java | Jun 3, 2026 | Jun 2, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub