Package
wildfly-openjdk-17
Component
antlr4
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
CVE-2026-13500 is a code injection issue in the ANTLR4 code-generation tool (grammar action blocks, OutputFile.java). WildFly bundles the antlr4 tool jar but never runs the ANTLR code generator at runtime; the issue is only exploitable when the ANTLR tool compiles an attacker-supplied grammar file. No fixed ANTLR4 release exists: 4.13.0 through 4.13.2 are all affected and 4.13.2 is the latest release.
Status