Apache
Apache Calcite: vulnerabilities and CVEs
Apache Calcite has 3 published vulnerabilities, 1 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs3
Last 12 months1
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46718 | Medium (6.5) | 0.69% | — | Jun 2, 2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. This issue affects Apache Calcite: from 1.5.0 before 1.42. Users are recommended to upgrade to version… |
| CVE-2022-39135 | Critical (9.8) | 2.2% | — | Sep 11, 2022 | Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, making them vulnerable to a potential… |
| CVE-2020-13955 | Medium (5.9) | 2.1% | — | Oct 9, 2020 | HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnerable to man-in-the-middle attacks. Calcite uses internally this method to connect with Druid and… |