Published on the oss-sec feed on 7 October 2026, authored by Gary D. Gregory and dated 6 October. The advisory covers nested Code and Record attributes that can cause unbounded recursion during parsing in ClassParser. Affected versions: Apache Commons BCEL before 6.13.0 and builds before commit 14890bf2b9014df25f9b4de86f29b5e917e5656b. Severity rated important: CVSS 3.1 score 5.9 (medium), vector AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N; CVSS 4.0 score 8.2 (high), vector AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N. The description points to a symbolic name not mapped to the correct object, with BCEL caching attacker-controlled classes. The text received is truncated, so the rest of the description should be read in the original source. Relevance: bytecode analysis libraries are often embedded in internal tools and transitive dependencies. To verify, look up the CVE identifier in official databases and the oss-sec listing, confirm the BCEL version in your project, and compare it with 6.13.0 or later. This text is a machine translation of the feed, not the official advisory.
Cyber ·
CVE-2026-94114: unbounded recursion in Apache Commons BCEL when parsing classes
Security advisory on nested Code and Record attributes that can cause unbounded recursion in the ClassParser of Apache Commons BCEL before 6.13.0. Severity rated important, with CVSS 3.1 at 5.9 and CVSS 4.0 at 8.2.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.