Over at Apache Commons VFS, we published two CVEs:
- CVE-2025-27553: Apache Commons VFS: Possible path traversal issue when using NameScope.DESCENDENT
- CVE-2025-30474: Apache Commons VFS: Failing to find an FTP file can reveal the URI's password in an error message
10 months ago