PkgRadar

Maven · repo1.maven.org

org.htmlunit:htmlunit-core-js

Java Dynamic Classload: URLClassLoader / defineClass — runs attacker-provided bytecode.

Why PkgRadar flagged 5.2.0

SeveritySignalEvidence
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · org/htmlunit/corejs/javascript/annotations/JSConstructor.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · org/htmlunit/corejs/javascript/annotations/JSFunction.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · org/htmlunit/corejs/javascript/annotations/JSGetter.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · org/htmlunit/corejs/javascript/annotations/JSSetter.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · org/htmlunit/corejs/javascript/annotations/JSStaticFunction.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · org/htmlunit/corejs/javascript/DefiningClassLoader.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · org/htmlunit/corejs/javascript/GeneratedClassLoader.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · org/htmlunit/corejs/javascript/JavaAdapter.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · org/htmlunit/corejs/javascript/LambdaConstructor.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · org/htmlunit/corejs/javascript/PolicySecurityController.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · org/htmlunit/corejs/javascript/ScriptableObject.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · org/htmlunit/corejs/javascript/SecureCaller.java

Scanned versions

VersionVerdictScoreScanned (UTC)
5.2.0Review252026-06-20

Block this in CI

PkgRadar gates org.htmlunit:htmlunit-core-js (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven org.htmlunit:[email protected]