MEDIUM 6.5
GHSA-c2rv-hwqm-wjpg
Apache Calcite is Vulnerable to Use of Externally-Controlled Input to Select Classes
Quick fix
GHSA-c2rv-hwqm-wjpg — org.apache.calcite:calcite-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>1.42.0</version> for org.apache.calcite:calcite-core Details
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite.
This issue affects Apache Calcite: from 1.5.0 before 1.42.
Users are recommended to upgrade to version 1.42, which fixes the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven / org.apache.calcite:calcite-core
Introduced in:
1.5.0 Fixed in: 1.42.0 Fix
# pom.xml: bump <version>1.42.0</version> for org.apache.calcite:calcite-core References
- https://nvd.nist.gov/vuln/detail/CVE-2026-46718 [ADVISORY]
- https://github.com/apache/calcite/commit/5855cfa14d8038e2a123ff6ce9722edce0e0cc25 [WEB]
- https://github.com/apache/calcite [PACKAGE]
- https://issues.apache.org/jira/browse/CALCITE-7532 [WEB]
- https://lists.apache.org/thread/9s37svo343w5ck1ovh478lkzcqk4949v [WEB]
- http://www.openwall.com/lists/oss-security/2026/06/01/7 [WEB]