Explore

Rule Explorer

Search the public rule index by CVE, GHSA, CWE, language, framework, author, or rule slug. Filter by language, framework, severity, confidence, license, and validation status.

Public rules
2917
Downloads
3.3M
Verified
2917
Authors
2
Search the rule indexUse CVE, GHSA, CWE, language, framework, package, or rule slug.
1 rules matched. Showing 1 loaded rules.
Publish rule
CVE-2026-46605: Activemq Insecure Factoryfindercve-2026-46605-activemq-insecure-factoryfinder

The single-argument constructor of `FactoryFinder` creates an insecure factory that instantiates classes via reflection without validating their type or origin. If user-controlled input determines the loaded class, this can lead to arbitrary code execution and initialization-based authorization bypass. Upgrade to the patched ActiveMQ version and use the thre

by Provallyupdated 2026-06-23Apache-2.0
7450 direct745 via packs
downloads
68quality
All matching rules loaded.