CVE-2025-48924 reported because of commons-lang jar version. When can we expect a new version with the fix?