GHSA-2p8h-ph4h-rm2fHighCVSS 5.9
Symbolic name not mapping to correct object vulnerability in Apache Commons. BCEL caches...
🔗 CVE IDs covered (1)
📋 Description
Symbolic name not mapping to correct object vulnerability in Apache Commons.
BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class.
This issue affects Apache Commons: before 6.13.0.
Users are recommended to upgrade to version 6.13.0, which fixes the issue.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-94114
- https://github.com/apache/commons-bcel/commit/14890bf2b9014df25f9b4de86f29b5e917e5656b.patch
- https://lists.apache.org/thread.html/d87nxx7nb5bombqggxhxo9lz16nwtsf9
- http://www.openwall.com/lists/oss-security/2026/10/07/12
- https://lists.apache.org/thread.html/co1wfk2lyrmpnfhn49o370pvfl978rw6
- https://github.com/advisories/GHSA-2p8h-ph4h-rm2f