Aias00 opened a new issue, #6727: URL: https://github.com/apache/shenyu/issues/6727
- Severity: Medium - Location: `shenyu-plugin/shenyu-plugin-api/src/main/java/org/apache/shenyu/plugin/api/utils/SpringBeanUtils.java:85` - Description: `beanFactory.setBeanClassLoader(classLoader); beanFactory.registerBeanDefinition(beanName, beanDefinition);`. `setBeanClassLoader` sets a single field on the shared `DefaultListableBeanFactory`, affecting type resolution for **all** beans, not just the one being registered. Every plugin registration overwrites the global classloader with that plugin's classloader. - Impact: Plugin A registers (factory CL ← A). Plugin B registers (factory CL ← B). Any deferred type resolution for A's beans (lazy autowire, AOP proxy, bean created on first use) now uses B's classloader, which cannot see A's classes → order-dependent `ClassNotFoundException`/`BeanCreationException`. - Suggested fix: Do not call `setBeanClassLoader` on the shared factory. Pass the classloader through the `BeanDefinition` (e.g. a custom `RootBeanDefinition` with a `Supplier` that does `Class.forName(name, false, pluginClassLoader)`). - Confidence: Medium - Related existing: SEC-1 (RCE via defineClass) is the trust issue; this is a separate classloader-correctness bug. --- _Identified during the 2026-08-02 deep re-scan; full list in [`docs/scan2-2026-08-02/06-medium-tiers.md`](docs/scan2-2026-08-02/06-medium-tiers.md)._ -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
