CVE-2026-46718
CVE-2026-46718 is a medium-severity vulnerability in Apache Calcite with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-470.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- EPSS exploit prediction: 1% (51st percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-33906
- Weakness: CWE-470
- Affected product: Apache Calcite
- Published:
- Last modified:
Description
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. This issue affects Apache Calcite: from 1.5.0 before 1.42. Users are recommended to upgrade to version 1.42, which fixes the issue.
Frequently asked questions
- What is CVE-2026-46718?
- Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. This issue affects Apache Calcite: from 1.5.0 before 1.42. Users are recommended to upgrade to version 1.42, which fixes the issue.
- How severe is CVE-2026-46718?
- CVE-2026-46718 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability none.
- Is CVE-2026-46718 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (51st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-46718?
- CVE-2026-46718 affects Apache Calcite. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-46718?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-46718 have an EU (EUVD) identifier?
- Yes. CVE-2026-46718 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-33906.
- When was CVE-2026-46718 published?
- CVE-2026-46718 was published on 2026-06-02 and last updated on 2026-07-22.
References
- https://lists.apache.org/thread/9s37svo343w5ck1ovh478lkzcqk4949v
- http://www.openwall.com/lists/oss-security/2026/06/01/7
Affected products (1)
- cpe:2.3:a:apache:calcite:*:*:*:*:*:*:*:*
More vulnerabilities in Apache Calcite
- CVE-2022-39135 — Critical (CVSS 9.8): Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not…
- CVE-2020-13955 — Medium (CVSS 5.9): HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients…
All CVEs affecting Apache Calcite →
Other CWE-470 (Unsafe Reflection) vulnerabilities
- CVE-2026-78030 — Critical (CVSS 9.8): DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in…
- CVE-2026-93762 — Critical (CVSS 9.8): Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that…
- CVE-2026-41871 — Critical (CVSS 9.8): Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')…
- CVE-2026-40008 — Critical (CVSS 9.8): Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. The…
- CVE-2026-42027 — Critical (CVSS 9.8): Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before…
- CVE-2025-34393 — Critical (CVSS 9.8): Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify…