CVE-2026-13502 PUBLISHED

antlr ANTLR4 Maven Plugin GrammarDependencies.java ObjectInputStream.readObject toctou

Assigner: VulDB
Reserved: 27.06.2026 Published: 28.06.2026 Updated: 28.06.2026

A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org/antlr/mojo/antlr4/GrammarDependencies.java of the component Maven Plugin. This manipulation causes time-of-check time-of-use. The attack is restricted to local execution. A high degree of complexity is needed for the attack. It is indicated that the exploitability is difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 2

Product Status

Vendor antlr
Product ANTLR4
Versions
  • Version 4.13.0 is affected
  • Version 4.13.1 is affected
  • Version 4.13.2 is affected

Credits

  • jiazhou (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Time-of-check Time-of-use CWE
  • Race Condition CWE