Skip to main content

Vendor/product archive

apache / calcite CVEs

Beta · best-effort

3 CVEs tagged to apache / calcite1 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-46718

Published Jun 2, 2026

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. This issue affects Apache Calcite: from 1.5.0 before 1.42. Us…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2022-39135

Published Sep 11, 2022

Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration,…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-13955

Published Oct 9, 2020

HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnerable to man-in-the-middle attacks. Calcite uses internally t…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1