<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Recent changes to support-requests</title><link>https://sourceforge.net/p/opencsv/support-requests/</link><description>Recent changes to support-requests</description><atom:link href="https://sourceforge.net/p/opencsv/support-requests/feed.rss" rel="self"/><language>en</language><lastBuildDate>Mon, 23 Feb 2026 15:29:06 -0000</lastBuildDate><atom:link href="https://sourceforge.net/p/opencsv/support-requests/feed.rss" rel="self" type="application/rss+xml"/><item><title>#130 Transitive dependency commons-lang3 vulnerable to CVE-2025-48924 — please upgrade to 3.20.0</title><link>https://sourceforge.net/p/opencsv/support-requests/130/?limit=25#511f</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;On my end, the reason I didn't question this is I wasn't expecting spring-boot to not be using the latest version. They decided not the backport the change to the 3.5 branch&lt;/p&gt;
&lt;p&gt;if you're curious: &lt;a href="https://github.com/spring-projects/spring-boot/issues/46437" rel="nofollow"&gt;https://github.com/spring-projects/spring-boot/issues/46437&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Also IntelliJ's dependency analyser doesn't tell me that the version is coming from spring-boot pining that version. &lt;/p&gt;
&lt;p&gt;Anyway thanks, problem solved ;) &lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Laurent T.</dc:creator><pubDate>Mon, 23 Feb 2026 15:29:06 -0000</pubDate><guid>https://sourceforge.net06e8a740cd0cdc5ce57b89ad8181d4595eaea2fc</guid></item><item><title>#130 Transitive dependency commons-lang3 vulnerable to CVE-2025-48924 — please upgrade to 3.20.0</title><link>https://sourceforge.net/p/opencsv/support-requests/130/?limit=25#76a0</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;No worries - I cannot count the number of times I have been personally burned by overriding transitive dependencies and so I am not surprised when I get a couple of these tickets every year.   I was just surprised that I had two this close together.  &lt;/p&gt;
&lt;p&gt;Scott :)&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Scott Conway</dc:creator><pubDate>Mon, 23 Feb 2026 15:21:42 -0000</pubDate><guid>https://sourceforge.netf40e9793f289a7733bf5664ef3cb0ab5f437357d</guid></item><item><title>#130 Transitive dependency commons-lang3 vulnerable to CVE-2025-48924 — please upgrade to 3.20.0</title><link>https://sourceforge.net/p/opencsv/support-requests/130/?limit=25#9b6f</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Hi Scott. &lt;/p&gt;
&lt;p&gt;Indeed, I don't know how I missed that. Seems I'm having the same issue described in that other ticket.&lt;/p&gt;
&lt;p&gt;Sorry for the dup. I'll be more careful in the future.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Laurent T.</dc:creator><pubDate>Mon, 23 Feb 2026 13:51:23 -0000</pubDate><guid>https://sourceforge.netdcd4b0bafbb7cfc16ab36b4ddcfbf645ccd3ebca</guid></item><item><title>#130 Transitive dependency commons-lang3 vulnerable to CVE-2025-48924 — please upgrade to 3.20.0</title><link>https://sourceforge.net/p/opencsv/support-requests/130/?limit=25#ec29</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Hello Laurent.  &lt;/p&gt;
&lt;p&gt;Make sure you are using version 5.12.0 as that is using 3.18.0.   If you are using 5.12.0 then look at &lt;a href="https://sourceforge.net/p/opencsv/feature-requests/175/"&gt;https://sourceforge.net/p/opencsv/feature-requests/175/&lt;/a&gt; for possible solution.   &lt;/p&gt;
&lt;p&gt;The snapshot version does use 3.20.0 but it is just dependency updates thus far so there has not been a reason to update.   Here again if you want to force 3.20.0 then look at the above feature request for the solution.&lt;/p&gt;
&lt;p&gt;Hope that helps. &lt;/p&gt;
&lt;p&gt;Scott Conway :)&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Scott Conway</dc:creator><pubDate>Mon, 23 Feb 2026 13:06:56 -0000</pubDate><guid>https://sourceforge.net8490c1a5b2be10faaaa1b5ebc19975aef2310a5c</guid></item><item><title>Transitive dependency commons-lang3 vulnerable to CVE-2025-48924 — please upgrade to 3.20.0</title><link>https://sourceforge.net/p/opencsv/support-requests/130/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Hi, just a heads-up that the transitive dependency org.apache.commons:commons-lang3 pulled in by opencsv is currently pinned to version 3.17.0, which is affected by CVE-2025-48924 (CVSS 5.3).&lt;/p&gt;
&lt;p&gt;The vulnerability involves uncontrolled recursion in ClassUtils.getClass(...), which can throw a StackOverflowError on very long inputs and potentially cause the application to stop. The fix was introduced in version 3.18.0.&lt;/p&gt;
&lt;p&gt;Would it be possible to upgrade this dependency to 3.20.0 (current latest)? Thanks for maintaining opencsv!&lt;/p&gt;
&lt;p&gt;Reference: &lt;a href="https://www.mend.io/vulnerability-database/CVE-2025-48924" rel="nofollow"&gt;https://www.mend.io/vulnerability-database/CVE-2025-48924&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Laurent Thoulon</dc:creator><pubDate>Mon, 23 Feb 2026 09:49:00 -0000</pubDate><guid>https://sourceforge.net24b888335408c79d0f223063fcd8c35c0f8c53d8</guid></item><item><title>Add column name or index information in CsvException</title><link>https://sourceforge.net/p/opencsv/support-requests/129/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;CsvDataTypeMismatchException exceptions do not have the index or column name. Could you add support for getting the column name or index information in the exception?&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">eltonsandre</dc:creator><pubDate>Mon, 17 Nov 2025 19:09:08 -0000</pubDate><guid>https://sourceforge.net654d4e4104986ae466041d80587e225959098a34</guid></item><item><title>#127 commons-beanutils update to 1.10.1</title><link>https://sourceforge.net/p/opencsv/support-requests/127/?limit=25#2cfb</link><description>&lt;div class="markdown_content"&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;: open --&amp;gt; closed&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Scott Conway</dc:creator><pubDate>Sun, 03 Aug 2025 17:11:26 -0000</pubDate><guid>https://sourceforge.net925549621036bd55dedbb1eb903a638d79b8cddf</guid></item><item><title>#128 Upate opencsv to take latest jar of commons-beanutils to fix CVE-2025-48734</title><link>https://sourceforge.net/p/opencsv/support-requests/128/?limit=25#80fd</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;commons-beanutils2 would also fix sonatype-2024-3350 as this is coming transitively from commons-collections 3.x&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Silviu Burcea</dc:creator><pubDate>Wed, 11 Jun 2025 14:32:26 -0000</pubDate><guid>https://sourceforge.netde6e18522151f0cb247664778b628bb97134ce48</guid></item><item><title>#127 commons-beanutils update to 1.10.1</title><link>https://sourceforge.net/p/opencsv/support-requests/127/?limit=25#8995</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;A better move would be to consider commons-beanutils2, as commons-beanutils 1.x contains commons-collections 3.x, which has sonatype-2024-3350&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Silviu Burcea</dc:creator><pubDate>Wed, 11 Jun 2025 14:29:50 -0000</pubDate><guid>https://sourceforge.net5f56856ed45fac83fe4639e0420a78a48fd4fac2</guid></item><item><title>Upate opencsv to take latest jar of commons-beanutils to fix CVE-2025-48734</title><link>https://sourceforge.net/p/opencsv/support-requests/128/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Need an update for opencsv to take latest jar of commons-beanutils to fix CVE-2025-48734. This CVE is a HIGH severity issue. &lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Kavita Torvi</dc:creator><pubDate>Thu, 05 Jun 2025 13:37:35 -0000</pubDate><guid>https://sourceforge.net11c85025aaf63be55debdc2c03a9643dd991717d</guid></item></channel></rss>