Measuring and Understanding Expectation Inconsistency in Java Libraries
Summary
Java libraries sometimes work differently than their developers intended, creating a security problem called 'expectation inconsistency' where programmers misuse the libraries and accidentally introduce vulnerabilities. Researchers created a tool called EIFinder that scanned nearly 30,000 popular Java libraries and found nearly 8,000 APIs (pre-built functions) with this problem, including 972 zero-day RCE (remote code execution, where attackers can run commands on a system) vulnerabilities affecting libraries from major companies like Google, Apache, and IBM.
Classification
Affected Vendors
Related Issues
Original source: http://ieeexplore.ieee.org/document/11622596
First tracked: August 10, 2026 at 08:04 PM
Classified by LLM (prompt v3) · confidence: 65%