CVE-2026-94114: Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in ClassParser
Symbolic name not mapping to correct object vulnerability in Apache Commons.
BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class.
This issue affects Apache Commons: before 6.13.0.
Users are recommended to upgrade to version 6.13.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Commons BCELto a version that resolves this vulnerability.Fixed in 6.13.0
Event History
Frequently Asked Questions
Which versions should be remediated?
Apache Commons BCEL versions before 6.13.0 are affected. Upgrade to version 6.13.0.
What attacker-controlled condition is involved?
The issue involves attacker-controlled classes whose self-declared names are cached without validation against the requested name. Subsequent lookups and name-keyed verification results can then refer to a different class.