8.2

CVE-2026-94114

Apache Commons BCEL: Class repositories cache class files under their self-declared names, enabling cache poisoning

Symbolic name not mapping to correct class.



BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class.



This issue affects Apache Commons BCEL: before 6.13.0.



Users are recommended to upgrade to version 6.13.0, which fixes the issue.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerApache Software Foundation
≫
Produkt Apache Commons BCEL
Default Statusunaffected
Version 0
Version < 6.13.0
Status affected
Version 0
Version < 14890bf2b9014df25f9b4de86f29b5e917e5656b
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.186
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Apache 8.2 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Apache 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE-386 Symbolic Name not Mapping to Correct Object

A constant symbolic reference to an object is used, even though the reference can resolve to a different object over time.

https://lists.apache.org/thread.html/co1wfk2lyrmpnfhn49o370pvfl978rw6
https://github.com/apache/commons-bcel/commit/14890bf2b9014df25f9b4de86f29b5e917e5656b.patch
http://www.openwall.com/lists/oss-security/2026/10/07/12