Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · net nu 137 bronnen 3 kritiek 32 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-94114

MEDIUM · 5.9 CVSS Gepubliceerd: CWE-386

Beschrijving

Symbolic name not mapping to correct object vulnerability in Apache Commons.

BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class.

This issue affects Apache Commons: before 6.13.0.

Users are recommended to upgrade to version 6.13.0, which fixes the issue.

References