Stack Overflow in JXPath
Description
CVE-2022-40160 is disputed; the reported vulnerability in Apache Commons JXPath was found to be invalid after maintainer review.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2022-40160 is disputed; the reported vulnerability in Apache Commons JXPath was found to be invalid after maintainer review.
CVE-2022-40160: Disputed Vulnerability in Apache Commons JXPath
This CVE was originally reported by the oss-fuzz project but has been disputed by the maintainers. The report failed to consider the intended security context of Apache Commons JXPath, which is designed to inspect and modify Java object graphs. The CVE allocation was performed by Google without contacting the JXPath maintainers, allegedly breaching CNA rules. After maintainer review, the reported issue was found to be invalid [1].
Apache Commons JXPath is a Java library implementing XPath 1.0 that can process XML and also inspect or modify Java object graphs (its explicit purpose) [2]. The disputed report likely misunderstood the library's design, as JXPath is intended to be used in controlled environments where the object graphs being accessed are trusted. No attack vector or exploitation details are acknowledged by the project.
There is no confirmed security impact. The official position is that the reported vulnerability does not apply given the library's intended usage. Users of Apache Commons JXPath are not required to take any action based on this CVE, as it has been rejected by the maintainers [1]. Patches or workarounds are not applicable since no actual security flaw was identified.
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
commons-jxpath:commons-jxpathMaven | <= 1.3 | — |
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-mqxp-cjr9-c5jmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-40160ghsaADVISORY
- bugs.chromium.org/p/oss-fuzz/issues/detailghsaWEB
News mentions
0No linked articles in our index yet.