Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.apache.calcite/calcite-core
  4. ›
  5. CVE-2026-46718

CVE-2026-46718: Apache Calcite is Vulnerable to Use of Externally-Controlled Input to Select Classes

June 2, 2026 (updated July 9, 2026)

Use of Externally-Controlled Input to Select Classes or Code (‘Unsafe Reflection’) vulnerability in Apache Calcite.

This issue affects Apache Calcite: from 1.5.0 before 1.42.

Users are recommended to upgrade to version 1.42, which fixes the issue.

References

  • github.com/advisories/GHSA-c2rv-hwqm-wjpg
  • github.com/apache/calcite/commit/5855cfa14d8038e2a123ff6ce9722edce0e0cc25
  • issues.apache.org/jira/browse/CALCITE-7532
  • lists.apache.org/thread/9s37svo343w5ck1ovh478lkzcqk4949v
  • nvd.nist.gov/vuln/detail/CVE-2026-46718

Code Behaviors & Features

Detect and mitigate CVE-2026-46718 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.5.0 before 1.42.0

Fixed versions

  • 1.42.0

Solution

Upgrade to version 1.42.0 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

Source file

maven/org.apache.calcite/calcite-core/CVE-2026-46718.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:17:29 +0000.