HIGH 8.2 NVD
CVE-2026-94114
Symbolic name not mapping to correct object vulnerability in Apache Commons. BCEL caches attacker-controlled classes under their self-declared names without
Symbolic name not mapping to correct object vulnerability in Apache Commons.
BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class.
This issue affects Apache Commons: before 6.13.0.
Users are recommended to upgrade to version 6.13.0, which fixes the issue.
References
- https://github.com/apache/commons-bcel/commit/14890bf2b9014df25f9b4de86f29b5e917e5656b.pat
- https://lists.apache.org/thread.html/d87nxx7nb5bombqggxhxo9lz16nwtsf9
This high severity vulnerability with a CVSS score of 8.2 was published on 2026-10-06 via NVD.
vulnfeed aggregates 9512 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.