CWE-470— Use of Externally-Controlled Input to Select Classes or Code (Unsafe Reflection)
The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.— MITRE CWE catalog
104 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-470page 3 of 3
- CVE-2026-8400CRITICALCVSS 9.8EG 9.82026-08-05
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and i…
- CVE-2026-86792HIGHCVSS 8.8EG 8.82026-09-16
Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hand them to the confluent-kafka cl…
- CVE-2026-93762CRITICALCVSS 9.8EG 9.82026-09-18
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unin…
- CVE-2026-93765CRITICALCVSS 9.1EG 9.12026-09-18
Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended intern…
Map vulnerabilities like CWE-470 to your infrastructure
EchelonGraph correlates every CVE — across CWE-470 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →