8.2
CVE-2026-94114
- EPSS 0.28%
- Veröffentlicht 06.10.2026 19:42:30
- Zuletzt bearbeitet 08.10.2026 06:16:45
- Erkennungen
Apache Commons BCEL: Class repositories cache class files under their self-declared names, enabling cache poisoning
Symbolic name not mapping to correct class. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class. This issue affects Apache Commons BCEL: before 6.13.0. Users are recommended to upgrade to version 6.13.0, which fixes the issue.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerApache Software Foundation
≫
Produkt
Apache Commons BCEL
Default Statusunaffected
Version
0
Version <
6.13.0
Status
affected
Version
0
Version <
14890bf2b9014df25f9b4de86f29b5e917e5656b
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.186 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Apache | 8.2 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| Apache | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-386 Symbolic Name not Mapping to Correct Object
A constant symbolic reference to an object is used, even though the reference can resolve to a different object over time.
https://lists.apache.org/thread.html/co1wfk2lyrmpnfhn49o370pvfl978rw6
https://github.com/apache/commons-bcel/commit/14890bf2b9014df25f9b4de86f29b5e917e5656b.patch
http://www.openwall.com/lists/oss-security/2026/10/07/12