Description
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. This issue affects Apache Calcite: from 1.5.0 before 1.42. Users are recommended to upgrade to version 1.42, which fixes the issue.
Problem types
CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
Product status
1.5.0 (semver) before 1.42
Credits
pyn3rd
uname
4ra1n
References
www.openwall.com/lists/oss-security/2026/06/01/7
lists.apache.org/thread/9s37svo343w5ck1ovh478lkzcqk4949v