Description
Symbolic name not mapping to correct object vulnerability in Apache Commons.



BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class.



This issue affects Apache Commons: before 6.13.0.



Users are recommended to upgrade to version 6.13.0, which fixes the issue.
Published: 2026-10-06
Score: 8.2 High
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
References

Wed, 07 Oct 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache commons Bcel
Vendors & Products Apache
Apache commons Bcel

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description Symbolic name not mapping to correct object vulnerability in Apache Commons. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class. This issue affects Apache Commons: before 6.13.0. Users are recommended to upgrade to version 6.13.0, which fixes the issue.
Title Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in ClassParser
Weaknesses CWE-386
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Apache Commons Bcel
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-07T06:12:16.240Z

Reserved: 2026-09-20T11:44:30.281Z

Link: CVE-2026-94114

cve-icon Vulnrichment

Updated: 2026-10-07T06:12:16.240Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:34.420

Modified: 2026-10-07T07:17:02.057

Link: CVE-2026-94114

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T04:00:09Z

Weaknesses
  • CWE-386

    Symbolic Name not Mapping to Correct Object