MEDIUM6.5
GHSA-c2rv-hwqm-wjpg
Apache Calcite is Vulnerable to Use of Externally-Controlled Input to Select Classes
Quick fix
GHSA-c2rv-hwqm-wjpg — org.apache.calcite:calcite-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>1.42.0</version> for org.apache.calcite:calcite-coreDetails
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite.
This issue affects Apache Calcite: from 1.5.0 before 1.42.
Users are recommended to upgrade to version 1.42, which fixes the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.apache.calcite:calcite-core
Introduced in:
1.5.0Fixed in: 1.42.0Fix
# pom.xml: bump <version>1.42.0</version> for org.apache.calcite:calcite-coreReferences
- https://nvd.nist.gov/vuln/detail/CVE-2026-46718[ADVISORY]
- https://github.com/apache/calcite/commit/5855cfa14d8038e2a123ff6ce9722edce0e0cc25[WEB]
- https://github.com/apache/calcite[PACKAGE]
- https://issues.apache.org/jira/browse/CALCITE-7532[WEB]
- https://lists.apache.org/thread/9s37svo343w5ck1ovh478lkzcqk4949v[WEB]
- http://www.openwall.com/lists/oss-security/2026/06/01/7[WEB]