#1150215 bcel: CVE-2026-94114

Package:
src:bcel
Source:
src:bcel
Submitter:
Salvatore Bonaccorso
Date:
2026-10-07 07:39:02 UTC
Severity:
normal
Tags:
#1150215#5
Date:
2026-10-07 07:38:07 UTC
From:
To:
Hi,

The following vulnerability was published for bcel.

CVE-2026-94114[0]:
| Symbolic name not mapping to correct object vulnerability in Apache
| Commons.    BCEL caches attacker-controlled classes under their
| self-declared names without validating the requested name, allowing
| subsequent lookups and name-keyed verification results to refer to a
| different class.    This issue affects Apache Commons: before
| 6.13.0.    Users are recommended to upgrade to version 6.13.0, which
| fixes the issue.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-94114
https://www.cve.org/CVERecord?id=CVE-2026-94114
[1] https://lists.apache.org/thread/d87nxx7nb5bombqggxhxo9lz16nwtsf9

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore