What's new in Klocwork 2026.3

Released September 2026

Here are the highlights for Klocwork 2026.3. If you're upgrading Klocwork, see the Limitations for items that might affect your upgrade or use.

New features and enhancements

This release includes the following enhancements.

Cancel project imports from the Web API

Administrators can now cancel queued or in-progress project imports through the Web API. The import_project action now returns the target project ID, and import_status reports the new cancelling and cancelled states so that you can track the operation.

To learn more, see Import projects using the Web API.

Take advantage of kwbazel enhancements

Kwbazel includes the following experimental enhancements:

  • Use --aspect_build with Bazel 6 or later to generate build specifications for Bazel builds using aspects as an alternative to the default aquery-based workflow.

  • Use --aspect_build for Bazel projects that delegate compilation to make, CMake, or gmake through rules_foreign_cc. Requires Bazel 7.1 or later.

  • Use --skip_build to skip the implicit bazel build step when you have already completed the build, reducing time in CI/CD pipelines.

  • Add support for remote Bazel build execution with new --remote_executor and --remote_cache arguments. Enhanced debugging with --debug and --show_progress options.

  • Support MODULE.bazel (bzlmod)-based Bazel projects with Bazel 7, Bazel 8, and Bazel 9. WORKSPACE-based Bazel projects continue to be supported with Bazel 6 and Bazel 7.

Improve LDAP connection recovery during builds

Klocwork now retries LDAP requests when a connection has been closed, to establish a new connection and continue the build instead of fail on the initial request. This improves build continuity in environments where LDAP connections may be dropped during normal operation.

Sync projects faster with kwxsync --module

Run kwxsync --module to scope a cross-project sync operation to only the defects belonging to a single module from the source project. Processing fewer defects results in faster sync times.

For more information, see Kwxsync.

Performance

In this release, you'll find performance improvements for the following:

  • kwant
  • kwcheck
  • kwciagent
  • kwgcheck
  • kwgradle
  • kwgradlew
  • kwmaven
  • kwmavenw

Connect Visual Studio Code to the Perforce SA MCP server

Support was added for connecting Visual Studio Code to the Perforce SA MCP server in standalone and PAG-bundled deployments. The documentation now covers the following:

  • Remote connection setup
  • Application token authentication
  • Configuration properties
  • Prerequisites and troubleshooting
  • Migration from local MCP configurations

To learn more, see Setting up the Perforce SA MCP server and Configure the Perforce SA MCP server.

Static analysis improvements

Use kwanalysis with the Perforce SCA MCP server

Instead of having to leave the AI assistant context to run Klocwork analysis, you can now start, track, and get the status of an analysis directly from any MCP-compatible AI assistant via the kw_start_analysis, kw_analysis_status, and kw_watch_analysis tools.

To learn more, see Perforce SA MCP server tools.

Use kwanalysis with the VS Code extension

The Perforce Static Analysis extension for VS Code now supports kwanalysis for version-agnostic local analysis workflows. When you configure or run local analysis for the extension, use kwanalysis instead of kwcheck.

For more information on configuring the VS Code extension, see Getting started with Perforce Static Analysis extension for Visual Studio Code.

Use upgraded ESLint for JavaScript analysis

Klocwork now bundles ESLint 8.57.1 for JavaScript analysis.

This may result in differences in JavaScript defect counts compared to release 2026.2. These differences (for example, higher or lower defect counts) reflect changes in analysis behavior and do not indicate that defects are being silently lost.

Use upgraded Gradle for kwgradle and kwgradlew

Klocwork now supports Gradle versions 3-9 for Kwgradle and Kwgradlew. For Gradle 9 projects, use Java 17+ for the Gradle daemon JVM.

For supported Gradle and Java versions, see Supported Java build tools.

Get improved analysis accuracy with conditional Read/Write knowledge base support

Klocwork now supports conditional Read/Write (R/W) knowledge base entries, allowing the analyzer to model function side effects more precisely. This improves dataflow accuracy and helps reduce certain false negatives, including some UNINIT-related cases. To enable the functionality, set your KW_RW_CONDITIONAL environment variable to 1. Because this feature performs additional analysis, enabling it may increase analysis time and, on some projects, the increase can be significant.

Resolve Java from additional locations

Klocwork bundles a Java 17 JRE in the _jvm folder along with the Validate server and Klocwork tools that require Java.

To determine which Java JRE versions and environment variables are used for running the Klocwork tools, the Validate server, and your build, see Java Virtual Machine requirements.

Klocwork tools now require Java 17 or later

The following tools that previously ran on Java 8 supplied through PATH or JAVA_HOME will now stop and show an error:

  • kwadmin
  • kwant
  • kwbuildproject
  • kwcheck
  • kwciagent
  • kwgcheck
  • kwgradle
  • kwgradlew
  • kwmaven
  • kwmavenw
  • kwxsync

Klocwork continues to include its own Java 17 runtime in this release, which is used before KW_JAVA. Since it will be removed in a future release, we recommend setting KW_JAVA to a Java 17+ java executable now.

You do not need to move your project to Java 17. Set JAVA_HOME to the Java version that your project is built with.

To learn more, see Java Virtual Machine requirements.

Coding standards

In this release, you'll find enhancements to the following taxonomy rules and recommendations:

  • Added OWASP Top 10 LLM 2026 C/C++, C#, and Java taxonomies, including checker mappings for recently introduced categories and coverage for LLM/AI-related weakness categories.

  • Added CWE Top 25 2025 C/C++, C#, and Java taxonomies, reflecting MITRE's 2025 list.

  • Added coverage for remaining CERT C/C++ L2 rules.

  • Updated the CWE ALL Java taxonomy to align with the CWE 4.20 release, including refreshed CWE guideline coverage.

Checkers

New checkers

Checker Description

CERT.CONC.COND_MULTIPLE_MUTEX

This CERT checker detects waits on the same POSIX condition variable with different mutexes, which can lead to undefined behavior.

CERT.CONC.LOCK.NO_RELEASE_ON_EXCEPTION

This CERT checker detects manually locked mutexes that are not guaranteed to be unlocked on all execution paths, including paths that exit because of an exception.

CERT.CTR.MUTABLE_PREDICATE

This CERT checker detects mutable predicate function objects and lambda predicates whose state changes can lead to unexpected results when standard library operations copy the predicate.

CERT.CTR.PTR_ARITH_POLYMORPHIC

This CERT checker detects when pointer arithmetic, including array subscripting, is used on polymorphic objects.

CERT.DCL.ODR.CLASS_REDEFINITION

This CERT checker detects cross-TU class/struct redefinition (the one-definition-rule violation).

CERT.ERR.UNCAUGHT_STATIC_INIT

This CERT checker detects static and thread-local objects whose construction, destruction, or initialization can throw outside a catchable scope.

CERT.EXCEPTION.SAFETY.ASSIGN_ORDER

This CERT checker detects assignment order that can leave an object in an unsafe state when an exception occurs.

CERT.EXPR.MOVED_FROM.RANGE

This CERT checker detects access to container elements in the moved-from range left by erase-remove algorithms such as std::remove, std::remove_if, and std::unique.

CERT.EXPR.MOVED_FROM.USE

This CERT checker detects use of an object after it has been moved, before the object is reinitialized.

CERT.EXPR.TEMP_OBJ.MOD

This CERT checker detects writes through objects with temporary lifetime, which can lead to undefined behavior. This checker is applicable only to the modern engine.

CERT.FIO.NO_POSITIONING

This CERT checker detects alternating input and output on the same C++ file stream without an intervening positioning call, which can result in undefined behavior.

CERT.FIO.RESET

Klocwork adds the CERT.FIO.RESET checker for code that uses strings after fgets() or fgetws() fails without resetting them.

CERT.STR_ACCESS.INVALID

This CERT checker detects uses of invalidated references, pointers, and iterators to access elements of a basic_string.

CXX.EMPTY.CATCH

This checker detects empty exception handlers that silently suppress exceptions without handling, logging, or propagating them.

ITER.RANGE.INVALID

This checker detects invalid iterator ranges passed to C++ STL algorithms, including reversed begin and end order and iterators from different containers.

JAVA.SV.LLM.APIKEY.HC

This checker flags hardcoded API keys in LLM client configuration to prevent disclosure of sensitive information.

JAVA.SV.LLM.CLIENT.NOTIMEOUT

This checker detects LLM client calls that do not configure a timeout, which can allow requests to consume resources longer than intended.

JAVA.SV.LLM.INPUT.UNBOUNDED

This checker detects unbounded input passed to an LLM, which can increase token usage and other resource consumption.

JAVA.SV.LLM.MODEL.DESERIAL

This checker detects unsafe deserialization of LLM output.

JAVA.SV.LLM.PROMPT.INJECTION

The checker detects when untrusted data (HTTP/servlet, streams, DOM, SOAP, socket, Struts, AWT/Swing sources) reaches the LLM prompt.

JAVA.SV.LLM.PROMPT.SECRET

This checker detects hardcoded secret values embedded in LLM prompt text.

JAVA.SV.LLM.SAFETY.DISABLED

This checker flags LLM client configurations that disable provider safety filtering.

JAVA.SV.LLM.TOOL.PRIV

This checker detects privileged or destructive LLM tool actions that do not enforce an authorization check.

JAVA.SV.LLM.VECTOR.NOFILTER

This checker detects vector or retrieval queries that do not apply tenant-scoped filtering, which can expose one user's data to another user.

NUM.OVERFLOW.DF.UNBOUNDED

This checker reports possible numeric overflow or wraparound whose violated bound is reached only through an unconstrained value, letting you triage or tune untrusted-source overflows separately from the concrete-value cases still reported by NUM.OVERFLOW.DF.

Modified checkers

Checker Description

SV.EXEC

This checker now treats LLM response text as an untrusted source when it is executed as an operating-system command.

SV.PATH

This checker now treats LLM response text as an untrusted source when it is used to build file and path names.

SV.SQL

This checker now treats LLM response text as an untrusted source when it is concatenated into SQL statements.

SV.XSS.REF

This checker now treats LLM response text as an untrusted source when it is written to reflected HTTP output.

Taxonomies

As part of the installation, you will find several custom taxonomy files that map Klocwork checkers to coding standards such as MISRA, CWE, OWASP, and DISA STIG.

Taxonomy Improvements

cpp_core_guidelines_community.tconf and cpp_core_guidelines_community_ja.tconf

Added new taxonomies for the C++ Core Guidelines.

autosar_cpp_18_10_strict.tconf and autosar_cpp_18_10_strict_ja.tconf

Added or modified checker mappings to the following rules:

  • M18-0-3
  • M18-2-1

cert_c_all.tconf and cert_c_all_ja.tconf

cert_c_rules.tconf and cert_c_rules_ja.tconf

Added or modified checker mappings to the following rules:

  • EXP35-C
  • FIO40-C
  • POS53-C

cert_cpp_rules.tconf and cert_cpp_rules_ja.tconf

Added or modified checker mappings to the following rules:

  • CON51-CPP
  • CTR58-CPP
  • DCL60-CPP
  • ERR56-CPP
  • ERR58-CPP
  • EXP63-CPP
  • FIO40-C
  • FIO50-CPP
  • POS53-C
cpp_core_guidelines_community.tconf and cpp_core_guidelines_community_ja.tconf

Added or modified checker mappings to the following rules:

  • R.12
  • R.22
  • R.23
  • ES.60
  • ES.84
  • ES.107
  • SL.io.2

cwe_all_cs.tconf and cwe_all_cs_ja.tconf

cwe_all_cxx.tconf and cwe_all_cxx_ja.tconf

cwe_all_java.tconf and cwe_all_java_ja.tconf

Substantial reorganization of the taxonomies.

Updated the CWE All Java taxonomy to align with the CWE 4.20 release, including refreshed CWE guideline coverage.

cwe_2025_top_25_cs.tconf and cwe_2025_top_25_cs_ja.tconf

cwe_2025_top_25_cxx.tconf and cwe_2025_top_25_cxx_ja.tconf

cwe_2025_top_25_java.tconf and cwe_2025_top_25_java_ja.tconf

Added CWE Top 25 2025 C/C++, C#, and Java taxonomies, reflecting MITRE's 2025 list.

disa_stig_v5_cs.tconf and disa_stig_v5_cs_ja.tconf

Added or modified checker mappings to the following rules:

  • V-222396 [APSC-DV-001980]
  • V-222566 [APSC-DV-001980]
disa_stig_v5_cxx.tconf and disa_stig_v5_cxx_ja.tconf

Added or modified checker mappings to the following rules:

  • V-222648 [APSC-DV-003170]
disa_stig_v5_java.tconf and disa_stig_v5_java_ja.tconf

Added or modified checker mappings to the following rules:

  • V-222604 [APSC-DV-002510]
disa_stig_v5_cs.tconf and disa_stig_v5_cs_ja.tconf

Added or modified checker mappings to the following rules:

  • V-265634 [APSC-DV-002010]
hkmc_c.tconf and hkmc_c_ja.tconf

Added or modified checker mappings to the following categories:

  • C-FIO-005
hkmc_cpp.tconf and hkmc_cpp_ja.tconf

Added or modified checker mappings to the following rules:

  • P-CON-002
  • P-CTR-004
  • P-DCL-011
  • P-ERR-007
  • P-ERR-009
  • P-EXP-011
  • P-STR-003
kw_quality_std_cxx.tconf and kw_quality_std_cxx_ja.tconf

Added or modified checker mappings to the following categories:

  • Suspicious Code Practices
misra_cpp_2023.tconf and misra_cpp_2023_ja.tconf

Added or modified checker mappings to the following rules:

  • 6.2.3

owasp_2026_10_llm_cs.tconf and owasp_2026_10_llm_cs_ja.tconf

owasp_2026_10_llm_cxx.tconf and owasp_2026_10_llm_cxx_ja.tconf

owasp_2026_10_llm_java.tconf and owasp_2026_10_llm_java_ja.tconf

Added OWASP Top 10 LLM 2026 C/C++, C#, and Java taxonomies, including checker mappings for recently introduced categories and coverage for LLM/AI-related weakness categories.

pci_3_2_1_cxx.tconf and pci_3_2_1_cxx_ja.tconf

Added or modified checker mappings to the following rules:

  • 6.5.1
perforce_qac.tconf and perforce_qac_ja.tconf

Added or modified checker mappings to the following categories:

  • Minor - Functions

Compilers

You'll find additional or improved support for the following compilers:

  • IAR iccarm
  • TI c7000
  • mwcceppc
  • QNX

For the full list of supported C and C++ compilers, see C/C++ compilers supported for build integration.

Licensing

Klocwork supports Reprise License Manager (RLM).

Changes to system requirements

Added support for the following environments:

  • Amazon Linux 2023
  • Apache Commons Bean Utilities 1.11.0
  • Apache Derby 10.14.2.0
  • Apache log4j 2.26.1
  • Apache Tomcat 10.1.59
  • Bouncy Castle 1.85
  • CLion 2025.2 (up to 2025.2.6.2), 2025.3 (up to 2025.3.6.1), 2026.1 (up to 2026.1.5)
  • Eclipse 4.2 (Juno) to 4.37 (2025-09)
  • ESLint 8.57.1
  • Expat 2.8.2
  • glibc 2.27 to 2.44
  • Google Chrome 140.x to 152.x
  • gradle/gradlew 3.x to 9.7.1
  • Guava 32.0.1
  • jackson-databind 2.21.5
  • jakarta.servlet-api 6.0.0
  • JetBrains IntelliJ IDEA 2025.3 (up to 2025.3.6.1)
  • Jetty 12.1.10
  • JQuery 3.7.1
  • jsoup 1.23.1
  • Logback 1.5.38
  • Maven Plugin API 3.8.1
  • MCP SDK 1.1.3
  • Microsoft Edge 140.x to 151.x
  • Mozilla Firefox 143.x to 154.x
  • Node.js 16.20.2
  • OpenJDK JRE 17.0.20_8
  • OpenSSL 3.5.7
  • Oracle Linux 9.8
  • Plexus 4.0.3
  • Spring AI 1.1.8
  • Spring Boot 3.5.16
  • SQLite 3.53.2
  • Visual Studio 2017 (up to 15.9.82), 2019 (up to 16.11.59), 2022 (up to 17.14.39)
  • Xerces 2.12.2

Ended support for the following environments:

  • AlmaLinux 9 to 9.8, 10 to 10.2

  • Amazon Linux 2

  • Apache Commons Bean Utilities 1.9.4

  • Apache Derby 10.10.1.1

  • Apache log4j 2.25.4

  • Apache Tomcat 10.1.49

  • Debian 11.0 to 11.11

  • ESLint 8.20

  • Expat 2.2.9

  • Fedora 42

  • Google Chrome 137.x to 139.x

  • Guava 31.1

  • Microsoft Edge 137.x to 139.x

  • Mozilla Firefox 140.x to 142.x

  • Node.js 16.16.0

  • OpenJDK JRE 1.8.0.372

  • OpenSSL 1.1.1c

  • SQLite 3.8.6

  • Ubuntu 18.04 to 18.04.6 LTS, 20.04 to 20.04.6 LTS

  • VS Code 1.101.2 to 1.104.2

For the complete list of supported versions, see the System Requirements.

Deprecations

  • Release 2026.3+: The bundled _jvm folder is planned for removal in 2026.4. Set KW_JAVA or JAVA_HOME so that your configuration continues to work after you upgrade.

  • Release 2026.3+: Support for Amazon Linux 2 ended in 2026.2 and has been removed from 2026.3. Amazon Linux 2023 is now supported.

  • Release 2026.2+: Support for Structure101 ended in 2024.3 and will be removed in a future release.

  • Release 2026.1+: The hybrid analysis engine has been removed from the Klocwork plugin for Visual Studio.

  • Release 2025.4+: The Klocwork Static Analysis plugin for Visual Studio is no longer provided or supported for Visual Studio 2015 in alignment with Microsoft's end of extended support for Visual Studio 2015.