Answer in brief
CVE-2022-39135 records a Critical severity (CVSS 9.8) vulnerability in Apache Calcite before 1.32.0 vulnerable to potential XML External Entity (XXE) attack. The current sources do not mark it as known exploited. The current feed maps org.apache.calcite:calcite-core (maven). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps org.apache.calcite:calcite-core (maven). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.calcite:calcite-coremaven | >=1.22.0,<1.32.0 | 1.32.0 |
Published upstream
Sep 12, 2022
Evidence: source:ghsa:source_dates:source-dates:recordSource modified
Sep 29, 2026
Evidence: source:ghsa:source_dates:source-dates:recordFirst seen by HOL
Sep 29, 2026
In Apache Calcite prior to version 1.32.0 the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, which makes them vulnerable to a potential XML External Entity (XXE) attack. Therefore any client exposing these operators, typically by using Oracle dialect (the first three) or MySQL dialect (the last one), is affected by this vulnerability (the extent of it will depend on the user under which the application is running). From Apache Calcite 1.32.0 onwards, Document Type Declarations and XML External Entity resolution are disabled on the impacted operators.
Quoted source text, attributed separately from HOL analysis.