Medium severity6.5NVD Advisory· Published Jun 2, 2026· Updated Jul 22, 2026
CVE-2026-46718
CVE-2026-46718
Description
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite.
This issue affects Apache Calcite: from 1.5.0 before 1.42.
Users are recommended to upgrade to version 1.42, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.calcite:calcite-coreMaven | >= 1.5.0, < 1.42.0 | 1.42.0 |
Affected products
7- osv-coords5 versionspkg:apk/chainguard/opensearch-3-sqlpkg:apk/chainguard/opensearch-fips-3-sqlpkg:apk/chainguard/solr-10-fullpkg:apk/chainguard/solr-fips-10-fullpkg:apk/wolfi/opensearch-3-sql
< 3.7.0-r3+ 4 more
- (no CPE)range: < 3.7.0-r3
- (no CPE)range: < 3.7.0-r3
- (no CPE)range: < 10.0.0-r12
- (no CPE)range: < 10.0.0-r6
- (no CPE)range: < 3.7.0-r3
Patches
Vulnerability mechanics
References
6- www.openwall.com/lists/oss-security/2026/06/01/7nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-c2rv-hwqm-wjpgghsaADVISORY
- lists.apache.org/thread/9s37svo343w5ck1ovh478lkzcqk4949vnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-46718ghsaADVISORY
- github.com/apache/calcite/commit/5855cfa14d8038e2a123ff6ce9722edce0e0cc25ghsaWEB
- issues.apache.org/jira/browse/CALCITE-7532ghsaWEB
News mentions
0No linked articles in our index yet.