VYPR
Moderate severityNVD Advisory· Published Oct 6, 2022· Updated Aug 3, 2024

Stack Overflow in JXPath

CVE-2022-40160

Description

CVE-2022-40160 is disputed; the reported vulnerability in Apache Commons JXPath was found to be invalid after maintainer review.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2022-40160 is disputed; the reported vulnerability in Apache Commons JXPath was found to be invalid after maintainer review.

CVE-2022-40160: Disputed Vulnerability in Apache Commons JXPath

This CVE was originally reported by the oss-fuzz project but has been disputed by the maintainers. The report failed to consider the intended security context of Apache Commons JXPath, which is designed to inspect and modify Java object graphs. The CVE allocation was performed by Google without contacting the JXPath maintainers, allegedly breaching CNA rules. After maintainer review, the reported issue was found to be invalid [1].

Apache Commons JXPath is a Java library implementing XPath 1.0 that can process XML and also inspect or modify Java object graphs (its explicit purpose) [2]. The disputed report likely misunderstood the library's design, as JXPath is intended to be used in controlled environments where the object graphs being accessed are trusted. No attack vector or exploitation details are acknowledged by the project.

There is no confirmed security impact. The official position is that the reported vulnerability does not apply given the library's intended usage. Users of Apache Commons JXPath are not required to take any action based on this CVE, as it has been rejected by the maintainers [1]. Patches or workarounds are not applicable since no actual security flaw was identified.

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
commons-jxpath:commons-jxpathMaven
<= 1.3

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.