CVE-2025-48924 | Apache Commons Lang up to 2.6/3.17.x ClassUtils.getClass recursion (EUVD-2025-21159 / Nessus ID 243262)
A vulnerability was found in Apache Commons Lang up to 2.6/3.17.x. It has been rated as problematic. The impacted element is the function ClassUtils.getClass. The manipulation leads to uncontrolled recursion.
This vulnerability is traded as CVE-2025-48924. Access to the local network is required for this attack to succeed. There is no exploit available.
Upgrading the affected component is advised.