Apache Commons BCEL Class Name Mapping Vulnerability (before 6.13.0)
CVE-2026-94114 Published on October 6, 2026

Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in ClassParser
Symbolic name not mapping to correct object vulnerability in Apache Commons. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class. This issue affects Apache Commons: before 6.13.0. Users are recommended to upgrade to version 6.13.0, which fixes the issue.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-94114 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
HIGH
Availability Impact:
NONE

Weakness Type

Symbolic Name not Mapping to Correct Object

A constant symbolic reference to an object is used, even though the reference can resolve to a different object over time.


Affected Versions

Apache Software Foundation Apache Commons BCEL: