Severity: low
Affected versions:
- Apache Calcite Avatica (org.apache.calcite.avatica:avatica-core) before
1.29.0
Description:
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe
Reflection') vulnerability in Apache Calcite Avatica. Plugin instantiation
(via AvaticaUtils#instantiatePlugin and other methods) initializes
arbitrary classes via unrestricted calls to Class.forName(String) which by
default triggers initialization. This may lead to the execution of static
initializer blocks in arbitrary classes present in the classpath. The
instantiation APIs should initialize and instantiate only classes
implementing the specified plugin interface passed as input in conjunction
with the desired classname. At the moment of writing, there are no
well-known or widely used classes with dangerous static initializer blocks
so the severity is low.
This issue affects Apache Calcite Avatica: before 1.29.0.
Users are recommended to upgrade to version 1.29.0, which fixes the issue.
This issue is being tracked as CALCITE-7610
Credit:
tinyb0y (finder)
ReturnZero (finder)
n0mi1k (finder)
Yan Xu (finder)
References:
https://calcite.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-70410
https://issues.apache.org/jira/browse/CALCITE-7610