CVE 6.5 MEDIUM

Apache Calcite: A user-controled model can load arbitrary classes, leading to code execution_CVE-2026-46718

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Description

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite.

This issue affects Apache Calcite: from 1.5.0 before 1.42.

Users are recommended to upgrade to version 1.42, which fixes the issue.

Basic Information

ID CVE-2026-46718
Source apache
Published Jun 2, 2026 at 09:17
Modified Jun 2, 2026 at 14:41

Affected Product

Vendor Apache Software Foundation
Product Apache Calcite
Version 1.5.0
Affected Versions Apache Software Foundation Apache Calcite 1.5.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.