Apache Commons BCEL Class Name Mapping Vulnerability (before 6.13.0)
CVE-2026-94114 Published on October 6, 2026
Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in ClassParser
Symbolic name not mapping to correct object vulnerability in Apache Commons.
BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class.
This issue affects Apache Commons: before 6.13.0.
Users are recommended to upgrade to version 6.13.0, which fixes the issue.
Vulnerability Analysis
CVE-2026-94114 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Weakness Type
Symbolic Name not Mapping to Correct Object
A constant symbolic reference to an object is used, even though the reference can resolve to a different object over time.
Affected Versions
Apache Software Foundation Apache Commons BCEL:- Before 6.13.0 is affected.
- Before 14890bf2b9014df25f9b4de86f29b5e917e5656b is affected.