CVE-2026-46718: Apache Calcite is Vulnerable to Use of Externally-Controlled Input to Select Classes
(updated )
Use of Externally-Controlled Input to Select Classes or Code (‘Unsafe Reflection’) vulnerability in Apache Calcite.
This issue affects Apache Calcite: from 1.5.0 before 1.42.
Users are recommended to upgrade to version 1.42, which fixes the issue.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-46718 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →