CVE-2026-49157: Insecure Dynamic Class Instantiation
Dynamically loading and instantiating classes without type validation can lead to Remote Code Execution (RCE). Ensure that dynamically resolved classes are validated against expected types before invoking `newInstance()`.
greprules fetch cve-2026-49157-insecure-dynamic-class-instantiation --engine opengrepDescription
Dynamically loading and instantiating classes without type validation can lead to Remote Code Execution (RCE). Ensure that dynamically resolved classes are validated against expected types before invoking `newInstance()`.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.