Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-94114— Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in ClassParser

Quick assessment

Affected
Apache Software Foundation Apache Commons BCEL
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Commons 中存在符号名称无法正确映射到对应对象的漏洞。 BCEL(字节码工程库)会将由攻击者控制的类以其自我声明的名称进行缓存,而不会验证所请求的名称是否合法。这导致后续的名称查找以及基于名称的验证结果可能指向不同的类。 该漏洞影响 Apache Commons 的 6.13.0 之前版本。 建议用户升级至 6.13.0 版本,该版本已修复此问题。

CVSS 5.9 · Medium

Affected Version Matrix 2

VendorProduct Version RangeStatus
Apache Software Foundation Apache Commons BCEL < 6.13.0 affected
< 14890bf2b9014df25f9b4de86f29b5e917e5656b affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-94114

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in ClassParser
Source: CVE Program / CVE List V5
Vulnerability Description
Symbolic name not mapping to correct object vulnerability in Apache Commons. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class. This issue affects Apache Commons: before 6.13.0. Users are recommended to upgrade to version 6.13.0, which fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
符号名称未能映射到正确对象
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Commons BCEL 0 ~ 6.13.0 -

II. Public POCs for CVE-2026-94114

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94114

请登录查看更多情报信息。

Other References for CVE-2026-94114 (2)

Same Patch Batch · Apache Software Foundation · 2026-10-06 · 8 CVEs total

CVE-2026-105244 5.3 MEDIUM Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content
CVE-2026-105243 5.3 MEDIUM Apache log4net: Oversize EventLogAppender record silently discarded
CVE-2026-105242 5.3 MEDIUM Apache log4net: Request validation failure drops the event in the aspnet-request converter
CVE-2026-105241 5.3 MEDIUM Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch
CVE-2026-105240 5.3 MEDIUM Apache log4net: NUL character truncates OutputDebugStringAppender records
CVE-2026-105239 5.3 MEDIUM Apache log4net: NUL character truncates EventLogAppender records
CVE-2026-105111 4.7 MEDIUM Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling stored XSS

IV. Related Vulnerabilities

V. Comments for CVE-2026-94114

No comments yet


Leave a comment