CWE-470: Unsafe Reflection
The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.
74 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-82078 — PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector
- CVE-2025-53693 — HTML Cache Poisoning through Unsafe Reflections
- CVE-2024-28121 — Reflex arbitrary method call in stimulus_reflex
- CVE-2025-2794 — Kentico Xperience <= 13.0.180 Unsafe Reflection
- CVE-2026-33157 — Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior
- CVE-2026-32264 — Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
- CVE-2026-32263 — Craft CMS vulnerable to behavior injection RCE via EntryTypesController
- CVE-2026-25498 — Craft has a potential authenticated Remote Code Execution via malicious attached Behavior
- CVE-2025-68455 — Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
- CVE-2025-12967 — An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low pr
- CVE-2025-34393 — Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCE
- CVE-2026-44416 — Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation
- CVE-2024-53850 — The Addressing GLPI plugin allows data enumeration through uncontrolled object instantiation
- CVE-2026-55559 — Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance)
- CVE-2026-46562 — Yamcs: Remote Code Execution via Mission Database algorithm override
- CVE-2026-40008 — Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC
- CVE-2024-4990 — Unsafe Reflection in base Component class in yiisoft/yii2
- CVE-2025-31119 — CWE-470 in generator-jhipster-entity-audit when having Javers selected as Entity Audit Framework
- CVE-2026-8178 — Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver
- CVE-2022-4993 — HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template
Recently published
- CVE-2026-41871 — Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)
- CVE-2026-41870 — Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)
- CVE-2026-58400 — GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter
- CVE-2026-19032 — jackson-databind resolves attacker-controlled URI schemes when deserializing java.nio.file.Path
- CVE-2026-55559 — Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance)
- CVE-2026-82078 — PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector
- CVE-2026-54614 — DebugKit: MailPreview contains unsafe reflection
- CVE-2026-79784 — Vocos through 0.1.0 Arbitrary Code Execution via Unrestricted class_path in Model Configuration
- CVE-2026-68508 — Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
- CVE-2026-63337 — RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading
- CVE-2026-13051 — Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template
- CVE-2022-4993 — HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template
- CVE-2026-19135 — OpenNMS JEXL sandbox bypass in Measurements REST API allows ROLE_USER to load arbitrary classes
- CVE-2026-44416 — Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation
- CVE-2026-17593 — Nexus Repository - Arbitrary Class Instantiation via Unsafe Realm Configuration
- CVE-2026-64663 — Statamic: Unsafe method invocation via Antlers template resolution allows data destruction
- CVE-2026-8400 — Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU
- CVE-2026-6020 — ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API
- CVE-2026-61536 — Banks: Unsafe importlib.import_module of attacker-controlled Tool.import_path in CompletionExtension allows RCE
- CVE-2026-53666 — React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration