CWE-470

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.

61 vulnerabilities with CWE-470
CVE-2026-48517 HIGH
MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments
CVSS 7.5
CVE-2026-48502 HIGH
MessagePack-CSharp ReadDateTime - Stack Overflow Denial of Service
CVSS 7.5
CVE-2026-49287 HIGH
Statamic CMS vulnerable to unsafe method invocation via collection sorting allows data destruction
CVSS 7.4
CVE-2026-48817 MEDIUM
Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
CVSS 5.3
CVE-2026-46718 MEDIUM
Apache Calcite: A user-controled model can load arbitrary classes, leading to code execution
CVSS 6.5
CVE-2026-34216 MEDIUM
CtrlPanel: Authenticated Remote Code Execution via Dynamic Class Instantiation in SettingsController.php
CVSS 6.6
CVE-2026-8178 HIGH
Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver
CVSS 8.1
CVE-2026-44339 HIGH
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
CVSS 8.6
CVE-2026-42027 CRITICAL
Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader
CVSS 9.8
CVE-2026-41175 HIGH
Statamic: Unsafe method invocation via query value resolution allows data destruction
CVSS 8.1
CVE-2026-23923 MEDIUM
Unauthenticated arbitrary PHP class instantiation
CVE-2026-33157 HIGH
Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior
CVSS 7.2
CVE-2026-32264 HIGH
Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
CVSS 7.2
CVE-2026-32263 HIGH
Craft CMS vulnerable to behavior injection RCE via EntryTypesController
CVSS 7.2
CVE-2026-25498 HIGH
Craft CMS 4.0.0-4.16.17 and 5.0.0-RC1-5.8.21 - Authenticated Remote Code Execution via Behavior Configuration Injection
CVSS 7.2
CVE-2025-68455 HIGH
Craft CMS 4.0.0.1-4.16.16 and 5.0.0-RC1-5.8.20 - Authenticated Remote Code Execution via Malicious Attached Behavior
CVSS 7.2
CVE-2025-34393 CRITICAL
Barracuda RMM < 2025.1.1 - Remote Code Execution via Insecure WSDL Reflection
CVSS 9.8
CVE-2025-12967 HIGH
AWS Wrappers for Amazon Aurora PostgreSQL - Privilege Escalation
CVSS 8.0
CVE-2025-63690 CRITICAL
pig-mesh Pig <= 3.8.2 Quartz - Reflection Remote Command Execution
CVSS 9.1
CVE-2025-61925 MEDIUM
Astro < 5.14.2 - Unsafe Reflection via X-Forwarded-Host Header
CVSS 6.5
CVE-2025-53693 CRITICAL
Sitecore XM/X <10.5 - Cache Poisoning
CVSS 9.8
CVE-2025-3600 HIGH
Progress Telerik UI for ASP.NET AJAX 2011.2.712-2025.1.218 - Denial of Service via Unsafe Reflection
CVSS 7.5
CVE-2025-31119 HIGH
generator-jhipster-entity-audit < 5.9.1 - Unsafe Reflection via Javers Entity Audit Framework
CVSS 7.6
CVE-2025-2794 HIGH
Kentico Xperience <= 13.0.180 - Unauthenticated Denial of Service via Unsafe Reflection
CVE-2024-4990 CRITICAL
yiisoft/yii2 2.0.48 - Code Injection
CVSS 9.1
Details
Vulnerabilities 61