CVE-2024-25710: Apache Commons Compress

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to upgrade to version 1.26.0 which fixes the issue.

Affected products

  • Apache Commons Compress: from 1.3, before 1.26.0 (fixed in 1.26.0)

Published 2024-02-19. Last modified 2026-06-17.