cbcvebase.

Apache Calcite vulnerabilities

3 known vulnerabilities affecting apache/calcite.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2022-39135P3CRITICALCVSS 9.8≥ 1.22.0, < 1.32.02022-09-11
CVE-2022-39135 [CRITICAL] CWE-611 CVE-2022-39135: Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRA Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, making them vulnerable to a potential XML External Entity (XXE) attack. Therefore any client exposing these operators, typically by using Oracle dialect (the first three
nvd
CVE-2026-46718P3MEDIUMCVSS 6.5≥ 1.5.0, < 1.42.02026-06-02
CVE-2026-46718 [MEDIUM] CWE-470 CVE-2026-46718: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. This issue affects Apache Calcite: from 1.5.0 before 1.42. Users are recommended to upgrade to version 1.42, which fixes the issue.
nvd
CVE-2020-13955P4MEDIUMCVSS 5.9fixed in 1.262020-10-09
CVE-2020-13955 [MEDIUM] CWE-295 CVE-2020-13955: HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections ma HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnerable to man-in-the-middle attacks. Calcite uses internally this method to connect with Druid and Splunk so information leakage may happen when using the respective Calcite adapters. The method itself is in a utility class so people
nvd