Skip to content

Address CVE in Apache Commons Lang3 #15

@lread

Description

@lread

Apache Commons Lang3 v3.14.0 is triggering CVE-2025-48924

This is addressed in Commons Lang v3.18.0.

This dep is brought in by Apache Commons Compress.

If we bump Apache Commons Compress from v1.26.0 to v1.28.0, we'll have addressed the CVE.

I'll follow up with a PR.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions