๐Ÿ” CVE Alert

CVE-2026-94114

MEDIUM 5.9

Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in ClassParser

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

Symbolic name not mapping to correct object vulnerability in Apache Commons. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class. This issue affects Apache Commons: before 6.13.0. Users are recommended to upgrade to version 6.13.0, which fixes the issue.

CWE CWE-386
Vendor apache software foundation
Product apache commons bcel
Published Oct 6, 2026
Last Updated Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache commons bcel

Be the first to know when new medium vulnerabilities affecting apache software foundation apache commons bcel are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

Apache Software Foundation / Apache Commons BCEL
0 < 6.13.0 0 < 14890bf2b9014df25f9b4de86f29b5e917e5656b

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apache/commons-bcel/commit/14890bf2b9014df25f9b4de86f29b5e917e5656b.patch lists.apache.org: https://lists.apache.org/thread.html/d87nxx7nb5bombqggxhxo9lz16nwtsf9

Credits

The Apache Software Foundation Claude Security