github / github/codeql

Java: static field access of unknown class breaks dataflow (build-mode=none)

Open
#19,597 3 comments 0 reactions 0 assignees View on GitHub
question
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

This is another issue we encountered when analysing databases created with `build-mode=none`.
It appears that dataflow graphs are broken when static fields are accessed on unknown classes.
Please take a look [codeql_issue2.zip](https://github.com/user-attachments/files/20458091/codeql_issue2.zip) for more information.

Here is the example java code:
```
// This import is from a dependency that is not resolved
import com.foo.mycompany.UnknownClass;

public class DataFlowNotConnected {
static class MyClass {
public static String staticField = "static";
}

private int run() {
// data source 1 should flow to sink e and f, but dataflow is broken by UnknownClass.staticField
int a = 1;
int b = a;

// static class field access from known class
String staticField1 = MyClass.staticField;

int c = b;
int d = c;

// static class field access from unknown class breaks dataflow
String staticField2 = UnknownClass.staticField;

int e = d;
int f = e;

return f;
}
}
```

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the example from codeql_issue2.zip with build-mode=none, focusing on the Java dataflow graph around UnknownClass.staticField. Compare the graph with and without that static access; done means the flow from a through d remains connected to sinks e and f.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
devtools, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.