GHSA-c2rv-hwqm-wjpgMediumCVSS 6.5
Apache Calcite is Vulnerable to Use of Externally-Controlled Input to Select Classes
🔗 CVE IDs covered (1)
📋 Description
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite.
This issue affects Apache Calcite: from 1.5.0 before 1.42.
Users are recommended to upgrade to version 1.42, which fixes the issue.
🎯 Affected products1
- maven/org.apache.calcite:calcite-core:>= 1.5.0, < 1.42.0
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-46718
- https://lists.apache.org/thread/9s37svo343w5ck1ovh478lkzcqk4949v
- http://www.openwall.com/lists/oss-security/2026/06/01/7
- https://github.com/apache/calcite/commit/5855cfa14d8038e2a123ff6ce9722edce0e0cc25
- https://issues.apache.org/jira/browse/CALCITE-7532
- https://github.com/advisories/GHSA-c2rv-hwqm-wjpg