PkgRadar

Maven · repo1.maven.org

tech.ydb.jdbc:ydb-jdbc-driver-shaded

Java Dynamic Classload: URLClassLoader / defineClass — runs attacker-provided bytecode.

Why PkgRadar flagged 2.3.26

SeveritySignalEvidence
mediumJava Dynamic ClassloadURLClassLoader / defineClass — runs attacker-provided bytecode. · tech/ydb/shaded/google/common/base/FinalizableReferenceQueue.java
highJava Static Init Side EffectStatic-initializer block contains process/network/reflection — runs on first class load. · tech/ydb/shaded/google/common/base/FinalizableReferenceQueue.java
mediumRemote Payloadmatched "cURL " · tech/ydb/jdbc/settings/YdbConfig.java

Scanned versions

VersionVerdictScoreScanned (UTC)
2.3.26High risk712026-06-11

Block this in CI

PkgRadar gates tech.ydb.jdbc:ydb-jdbc-driver-shaded (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven tech.ydb.jdbc:[email protected]