CVE-2026-94114
Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in ClassParser
CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th
Symbolic name not mapping to correct object vulnerability in Apache Commons. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class. This issue affects Apache Commons: before 6.13.0. Users are recommended to upgrade to version 6.13.0, which fixes the issue.
| CWE | CWE-386 |
| Vendor | apache software foundation |
| Product | apache commons bcel |
| Published | Oct 6, 2026 |
| Last Updated | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache commons bcel
Be the first to know when new medium vulnerabilities affecting apache software foundation apache commons bcel are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Affected Versions
Apache Software Foundation / Apache Commons BCEL
0 < 6.13.0 0 < 14890bf2b9014df25f9b4de86f29b5e917e5656b
References
Credits
The Apache Software Foundation Claude Security