An RCE vulnerability (CVSS 9.8) in Apache Commons Text, exploitable via specific usage patterns. Active scanning from Russian and Chinese IP space was observed shortly after disclosure. Frequently compared to Log4Shell given the Apache Commons pedigree.
VULN_RECENT_FREQUENCY + maintainer health preconditions
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | VULN_RECENT_FREQUENCY + maintainer health preconditions |
| Socket | After damage | Detects after CVE published |
| Snyk | After damage | CVE detection after publication; reactive not proactive |
| Sonatype (Nexus) | After damage | Detects after CVE published |
| Black Duck | After damage | Detects after CVE published |
| Endor Labs | After damage | CVE detection + reachability analysis after publication; reactive |