Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <0a0cd424-a10d-a743-df81-475c9f3fdd6a@apache.org>
Date: Tue, 06 Oct 2026 19:38:04 +0000
From: "Gary D. Gregory" <ggregory@...che.org>
To: oss-security@...ts.openwall.com
Subject: CVE-2026-94114: Apache Commons BCEL: Nested Code/Record attributes
 drive unbounded parse-time recursion in ClassParser 

Severity: important 
    CVSS 3.1: 5.9 (medium) CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
    CVSS 4.0: 8.2 (high) CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Affected versions:

- Apache Commons BCEL before 6.13.0
- Apache Commons BCEL before 14890bf2b9014df25f9b4de86f29b5e917e5656b

Description:

Symbolic name not mapping to correct object vulnerability in Apache Commons.



BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class.



This issue affects Apache Commons: before 6.13.0.



Users are recommended to upgrade to version 6.13.0, which fixes the issue.

Credit:

The Apache Software Foundation (finder)
Claude Security (tool)

References:

https://github.com/apache/commons-bcel/commit/14890bf2b9014df25f9b4de86f29b5e917e5656b.patch
https://commons.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-94114

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.