VYPR
Moderate severityNVD Advisory· Published Oct 6, 2022· Updated Aug 3, 2024

Stack Overflow in JXPath

CVE-2022-40159

Description

CVE-2022-40159 is a disputed vulnerability in Apache Commons JXPath; the original report was invalid and the CVE allocation was contested by maintainers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2022-40159 is a disputed vulnerability in Apache Commons JXPath; the original report was invalid and the CVE allocation was contested by maintainers.

Overview

CVE-2022-40159 was originally reported by the oss-fuzz project as a security issue in Apache Commons JXPath. However, the report failed to consider the intended security context of the library, and the CVE was allocated without proper coordination with the JXPath maintainers. After review, the maintainers determined the report to be invalid [1].

Context

Apache Commons JXPath is a Java library that implements XPath 1.0 and is explicitly designed to inspect and modify Java object graphs, as well as mixed Java/XML structures [2]. The library's purpose is to provide a flexible way to navigate object graphs, which inherently involves accessing arbitrary properties. The oss-fuzz report did not account for this design, leading to a misinterpretation of the behavior as a vulnerability.

Impact and

Status Because the reported issue is not a valid vulnerability, there is no security impact. The CVE record remains disputed, and no patch or workaround is necessary. Users of Apache Commons JXPath can continue using the library as intended without security concerns [1].

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
commons-jxpath:commons-jxpathMaven
<= 1.3

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.