Heads up CVE watchers! We just published CVE-2025-48976: Apache Commons FileUpload: DoS via part headers. Pick up version 1.6.0 or 2.0.0-M4 https://t.co/OnoNtxXRpg #cve#apache#security
Here are the latest Apache Commons releases:
- JXPATH-1.4.0: 2025-04-18
- JEXL-3.5.0: 2025-04-16
- IO-2.19.0: 2025-04-12
- TEXT-1.13.1: 2025-04-10
Come see us: https://t.co/7VT1A6mlqk
Over at Apache Commons VFS, we published two CVEs:
- CVE-2025-27553: Apache Commons VFS: Possible path traversal issue when using NameScope.DESCENDENT
- CVE-2025-30474: Apache Commons VFS: Failing to find an FTP file can reveal the URI's password in an error message
I am pleased to announce Apache Commons CSV 1.14.0.
Commons CSV reads and writes files in Comma Separated Value (CSV) format variations.
See https://t.co/iiP102qxIU
The Apache Commons VFS Project team is pleased to announce the release of Apache Commons VFS Project 2.10.0.
Apache Commons VFS is a Virtual File System library for Java 8 or later.
https://t.co/ShOKPZN7d0
#theASF#ApacheCommons
The Apache Commons BeanUtils team is pleased to announce the release of Apache Commons BeanUtils 1.10.1.
This is our old-school Java Bean utility library available at https://t.co/z488Fqz0dD
#theASF#ApacheCommons
The Apache Commons team is pleased to announce Apache Commons Logging 1.3.5.
Commons Logging is a thin adapter allowing configurable bridging to other, well-known logging systems.
Historical list of changes: https://t.co/kJONsEfqmP
Website: https://t.co/xuZl7ynvwY
The Apache Commons Codec team announces the release of Apache Commons Codec 1.18.0.
Commons Codec contains encodes and decodes Base16, Base32, Base64, digest, and Hexadecimal. The codec package also maintains a collection of phonetic encoding utilities.
https://t.co/kGWCMafA5E
The Apache Commons Pool team announces the release of Apache Commons Pool 2.12.1.
Commons Pool provides an object-pooling API and several object-pool implementations, with robust instance
tracking and pool monitoring.
https://t.co/icuqxrresV
The Apache Commons team announces Commons Codec 1.17.2 for #Java
Codec contains encoders and decoders for formats such as Base16, Base32, Base64, digest, and Hexadecimal. The codec package also maintains a collection of phonetic encoding utilities.
See https://t.co/kGWCMafA5E