PkgRadar

Maven · repo1.maven.org

org.questdb:questdb

Java Dynamic Classload: URLClassLoader / defineClass — runs attacker-provided bytecode.

Why PkgRadar flagged 9.4.3

SeveritySignalEvidence
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · io/questdb/cairo/map/RecordValueSinkFactory.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · io/questdb/cairo/RecordSinkFactory.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · io/questdb/std/datetime/microtime/MicrosFormatCompiler.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · io/questdb/std/BytecodeAssembler.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · io/questdb/griffin/engine/groupby/GroupByFunctionsUpdaterFactory.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · io/questdb/griffin/engine/orderby/RecordComparatorCompiler.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · io/questdb/std/datetime/nanotime/NanosFormatCompiler.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · io/questdb/std/datetime/millitime/DateFormatCompiler.java
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · io/questdb/griffin/RecordToRowCopierUtils.java
mediumJava Static Init Side EffectStatic-initializer block contains process/network/reflection — runs on first class load (contributory signal). · io/questdb/cutlass/http/HttpResponseSink.java
mediumLarge Native Blob8059072 bytes · io/questdb/bin/linux-x86-64/libquestdbr.so
mediumLarge Native Blob7252992 bytes · io/questdb/bin/windows-x86-64/questdbr.dll

Scanned versions

VersionVerdictScoreScanned (UTC)
9.4.3Review332026-06-15

Block this in CI

PkgRadar gates org.questdb:questdb (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven org.questdb:[email protected]