Behrad's Blog
Posts
Tags
Behrad's Blog
Posts
Tags
×
cwe-470
2026
January 27, 2026
Unsafe Reflection Vulnerabilities
How unsafe reflection turns user input into arbitrary class instantiation, from the mechanics of CWE-470 to exploitation and prevention across Java and Ruby.