What's new in Klocwork 2026.3
Released September 2026
Here are the highlights for Klocwork 2026.3. If you're upgrading Klocwork, see the Limitations for items that might affect your upgrade or use.
New features and enhancements
This release includes the following enhancements.
Cancel project imports from the Web API
Administrators can now cancel queued or in-progress project imports through the Web API. The import_project action now returns the target project ID, and import_status reports the new cancelling and cancelled states so that you can track the operation.
To learn more, see Import projects using the Web API.
Take advantage of kwbazel enhancements
Kwbazel includes the following experimental enhancements:
-
Use
--aspect_buildwith Bazel 6 or later to generate build specifications for Bazel builds using aspects as an alternative to the default aquery-based workflow. -
Use
--aspect_buildfor Bazel projects that delegate compilation tomake,CMake, orgmakethroughrules_foreign_cc. Requires Bazel 7.1 or later. -
Use
--skip_buildto skip the implicitbazel buildstep when you have already completed the build, reducing time in CI/CD pipelines. -
Add support for remote Bazel build execution with new
--remote_executorand--remote_cachearguments. Enhanced debugging with--debugand--show_progressoptions. -
Support MODULE.bazel (bzlmod)-based Bazel projects with Bazel 7, Bazel 8, and Bazel 9. WORKSPACE-based Bazel projects continue to be supported with Bazel 6 and Bazel 7.
Improve LDAP connection recovery during builds
Klocwork now retries LDAP requests when a connection has been closed, to establish a new connection and continue the build instead of fail on the initial request. This improves build continuity in environments where LDAP connections may be dropped during normal operation.
Sync projects faster with kwxsync --module
Run kwxsync --module to scope a cross-project sync operation to only the defects belonging to a single module from the source project. Processing fewer defects results in faster sync times.
For more information, see Kwxsync.
Performance
In this release, you'll find performance improvements for the following:
- kwant
- kwcheck
- kwciagent
- kwgcheck
- kwgradle
- kwgradlew
- kwmaven
- kwmavenw
Connect Visual Studio Code to the Perforce SA MCP server
Support was added for connecting Visual Studio Code to the Perforce SA MCP server in standalone and PAG-bundled deployments. The documentation now covers the following:
- Remote connection setup
- Application token authentication
- Configuration properties
- Prerequisites and troubleshooting
- Migration from local MCP configurations
To learn more, see Setting up the Perforce SA MCP server and Configure the Perforce SA MCP server.
Static analysis improvements
Use kwanalysis with the Perforce SCA MCP server
Instead of having to leave the AI assistant context to run Klocwork analysis, you can now start, track, and get the status of an analysis directly from any MCP-compatible AI assistant via the kw_start_analysis, kw_analysis_status, and kw_watch_analysis tools.
To learn more, see Perforce SA MCP server tools.
Use kwanalysis with the VS Code extension
The Perforce Static Analysis extension for VS Code now supports kwanalysis for version-agnostic local analysis workflows. When you configure or run local analysis for the extension, use kwanalysis instead of kwcheck.
For more information on configuring the VS Code extension, see Getting started with Perforce Static Analysis extension for Visual Studio Code.
Use upgraded ESLint for JavaScript analysis
Klocwork now bundles ESLint 8.57.1 for JavaScript analysis.
This may result in differences in JavaScript defect counts compared to release 2026.2. These differences (for example, higher or lower defect counts) reflect changes in analysis behavior and do not indicate that defects are being silently lost.
Use upgraded Gradle for kwgradle and kwgradlew
Klocwork now supports Gradle versions 3-9 for Kwgradle and Kwgradlew. For Gradle 9 projects, use Java 17+ for the Gradle daemon JVM.
For supported Gradle and Java versions, see Supported Java build tools.
Get improved analysis accuracy with conditional Read/Write knowledge base support
Klocwork now supports conditional Read/Write (R/W) knowledge base entries, allowing the analyzer to model function side effects more precisely. This improves dataflow accuracy and helps reduce certain false negatives, including some UNINIT-related cases. To enable the functionality, set your KW_RW_CONDITIONAL environment variable to 1. Because this feature performs additional analysis, enabling it may increase analysis time and, on some projects, the increase can be significant.
Resolve Java from additional locations
Klocwork bundles a Java 17 JRE in the _jvm folder along with the Validate server and Klocwork tools that require Java.
To determine which Java JRE versions and environment variables are used for running the Klocwork tools, the Validate server, and your build, see Java Virtual Machine requirements.
Klocwork tools now require Java 17 or later
The following tools that previously ran on Java 8 supplied through PATH or JAVA_HOME will now stop and show an error:
- kwadmin
- kwant
- kwbuildproject
- kwcheck
- kwciagent
- kwgcheck
- kwgradle
- kwgradlew
- kwmaven
- kwmavenw
- kwxsync
Klocwork continues to include its own Java 17 runtime in this release, which is used before KW_JAVA. Since it will be removed in a future release, we recommend setting KW_JAVA to a Java 17+ java executable now.
You do not need to move your project to Java 17. Set JAVA_HOME to the Java version that your project is built with.
To learn more, see Java Virtual Machine requirements.
Coding standards
In this release, you'll find enhancements to the following taxonomy rules and recommendations:
-
Added OWASP Top 10 LLM 2026 C/C++, C#, and Java taxonomies, including checker mappings for recently introduced categories and coverage for LLM/AI-related weakness categories.
-
Added CWE Top 25 2025 C/C++, C#, and Java taxonomies, reflecting MITRE's 2025 list.
-
Added coverage for remaining CERT C/C++ L2 rules.
-
Updated the CWE ALL Java taxonomy to align with the CWE 4.20 release, including refreshed CWE guideline coverage.
Checkers
New checkers
| Checker | Description |
|---|---|
|
CERT.CONC.COND_MULTIPLE_MUTEX |
This CERT checker detects waits on the same POSIX condition variable with different mutexes, which can lead to undefined behavior. |
|
CERT.CONC.LOCK.NO_RELEASE_ON_EXCEPTION |
This CERT checker detects manually locked mutexes that are not guaranteed to be unlocked on all execution paths, including paths that exit because of an exception. |
|
CERT.CTR.MUTABLE_PREDICATE |
This CERT checker detects mutable predicate function objects and lambda predicates whose state changes can lead to unexpected results when standard library operations copy the predicate. |
|
CERT.CTR.PTR_ARITH_POLYMORPHIC |
This CERT checker detects when pointer arithmetic, including array subscripting, is used on polymorphic objects. |
|
CERT.DCL.ODR.CLASS_REDEFINITION |
This CERT checker detects cross-TU class/struct redefinition (the one-definition-rule violation). |
|
CERT.ERR.UNCAUGHT_STATIC_INIT |
This CERT checker detects static and thread-local objects whose construction, destruction, or initialization can throw outside a catchable scope. |
|
CERT.EXCEPTION.SAFETY.ASSIGN_ORDER |
This CERT checker detects assignment order that can leave an object in an unsafe state when an exception occurs. |
|
CERT.EXPR.MOVED_FROM.RANGE |
This CERT checker detects access to container elements in the moved-from range left by erase-remove algorithms such as |
|
CERT.EXPR.MOVED_FROM.USE |
This CERT checker detects use of an object after it has been moved, before the object is reinitialized. |
|
CERT.EXPR.TEMP_OBJ.MOD |
This CERT checker detects writes through objects with temporary lifetime, which can lead to undefined behavior. This checker is applicable only to the modern engine. |
|
CERT.FIO.NO_POSITIONING |
This CERT checker detects alternating input and output on the same C++ file stream without an intervening positioning call, which can result in undefined behavior. |
|
CERT.FIO.RESET |
Klocwork adds the CERT.FIO.RESET checker for code that uses strings after |
|
CERT.STR_ACCESS.INVALID |
This CERT checker detects uses of invalidated references, pointers, and iterators to access elements of a |
|
CXX.EMPTY.CATCH |
This checker detects empty exception handlers that silently suppress exceptions without handling, logging, or propagating them. |
|
ITER.RANGE.INVALID |
This checker detects invalid iterator ranges passed to C++ STL algorithms, including reversed begin and end order and iterators from different containers. |
|
JAVA.SV.LLM.APIKEY.HC |
This checker flags hardcoded API keys in LLM client configuration to prevent disclosure of sensitive information. |
|
JAVA.SV.LLM.CLIENT.NOTIMEOUT |
This checker detects LLM client calls that do not configure a timeout, which can allow requests to consume resources longer than intended. |
|
JAVA.SV.LLM.INPUT.UNBOUNDED |
This checker detects unbounded input passed to an LLM, which can increase token usage and other resource consumption. |
|
JAVA.SV.LLM.MODEL.DESERIAL |
This checker detects unsafe deserialization of LLM output. |
|
JAVA.SV.LLM.PROMPT.INJECTION |
The checker detects when untrusted data (HTTP/servlet, streams, DOM, SOAP, socket, Struts, AWT/Swing sources) reaches the LLM prompt. |
|
JAVA.SV.LLM.PROMPT.SECRET |
This checker detects hardcoded secret values embedded in LLM prompt text. |
|
JAVA.SV.LLM.SAFETY.DISABLED |
This checker flags LLM client configurations that disable provider safety filtering. |
| JAVA.SV.LLM.TOOL.PRIV |
This checker detects privileged or destructive LLM tool actions that do not enforce an authorization check. |
| JAVA.SV.LLM.VECTOR.NOFILTER |
This checker detects vector or retrieval queries that do not apply tenant-scoped filtering, which can expose one user's data to another user. |
|
NUM.OVERFLOW.DF.UNBOUNDED |
This checker reports possible numeric overflow or wraparound whose violated bound is reached only through an unconstrained value, letting you triage or tune untrusted-source overflows separately from the concrete-value cases still reported by NUM.OVERFLOW.DF. |
Modified checkers
| Checker | Description |
|---|---|
|
SV.EXEC |
This checker now treats LLM response text as an untrusted source when it is executed as an operating-system command. |
|
SV.PATH |
This checker now treats LLM response text as an untrusted source when it is used to build file and path names. |
|
SV.SQL |
This checker now treats LLM response text as an untrusted source when it is concatenated into SQL statements. |
|
SV.XSS.REF |
This checker now treats LLM response text as an untrusted source when it is written to reflected HTTP output. |
Taxonomies
As part of the installation, you will find several custom taxonomy files that map Klocwork checkers to coding standards such as MISRA, CWE, OWASP, and DISA STIG.
| Taxonomy | Improvements |
|---|---|
|
cpp_core_guidelines_community.tconf and cpp_core_guidelines_community_ja.tconf |
Added new taxonomies for the C++ Core Guidelines. |
|
autosar_cpp_18_10_strict.tconf and autosar_cpp_18_10_strict_ja.tconf |
Added or modified checker mappings to the following rules:
|
|
cert_c_all.tconf and cert_c_all_ja.tconf cert_c_rules.tconf and cert_c_rules_ja.tconf |
Added or modified checker mappings to the following rules:
|
|
cert_cpp_rules.tconf and cert_cpp_rules_ja.tconf |
Added or modified checker mappings to the following rules:
|
| cpp_core_guidelines_community.tconf and cpp_core_guidelines_community_ja.tconf |
Added or modified checker mappings to the following rules:
|
|
cwe_all_cs.tconf and cwe_all_cs_ja.tconf cwe_all_cxx.tconf and cwe_all_cxx_ja.tconf cwe_all_java.tconf and cwe_all_java_ja.tconf |
Substantial reorganization of the taxonomies. Updated the CWE All Java taxonomy to align with the CWE 4.20 release, including refreshed CWE guideline coverage. |
|
cwe_2025_top_25_cs.tconf and cwe_2025_top_25_cs_ja.tconf cwe_2025_top_25_cxx.tconf and cwe_2025_top_25_cxx_ja.tconf cwe_2025_top_25_java.tconf and cwe_2025_top_25_java_ja.tconf |
Added CWE Top 25 2025 C/C++, C#, and Java taxonomies, reflecting MITRE's 2025 list. |
| disa_stig_v5_cs.tconf and disa_stig_v5_cs_ja.tconf |
Added or modified checker mappings to the following rules:
|
| disa_stig_v5_cxx.tconf and disa_stig_v5_cxx_ja.tconf |
Added or modified checker mappings to the following rules:
|
| disa_stig_v5_java.tconf and disa_stig_v5_java_ja.tconf |
Added or modified checker mappings to the following rules:
|
| disa_stig_v5_cs.tconf and disa_stig_v5_cs_ja.tconf |
Added or modified checker mappings to the following rules:
|
| hkmc_c.tconf and hkmc_c_ja.tconf |
Added or modified checker mappings to the following categories:
|
| hkmc_cpp.tconf and hkmc_cpp_ja.tconf |
Added or modified checker mappings to the following rules:
|
| kw_quality_std_cxx.tconf and kw_quality_std_cxx_ja.tconf |
Added or modified checker mappings to the following categories:
|
| misra_cpp_2023.tconf and misra_cpp_2023_ja.tconf |
Added or modified checker mappings to the following rules:
|
|
owasp_2026_10_llm_cs.tconf and owasp_2026_10_llm_cs_ja.tconf owasp_2026_10_llm_cxx.tconf and owasp_2026_10_llm_cxx_ja.tconf owasp_2026_10_llm_java.tconf and owasp_2026_10_llm_java_ja.tconf |
Added OWASP Top 10 LLM 2026 C/C++, C#, and Java taxonomies, including checker mappings for recently introduced categories and coverage for LLM/AI-related weakness categories. |
| pci_3_2_1_cxx.tconf and pci_3_2_1_cxx_ja.tconf |
Added or modified checker mappings to the following rules:
|
| perforce_qac.tconf and perforce_qac_ja.tconf |
Added or modified checker mappings to the following categories:
|
Compilers
You'll find additional or improved support for the following compilers:
- IAR iccarm
- TI c7000
- mwcceppc
- QNX
For the full list of supported C and C++ compilers, see C/C++ compilers supported for build integration.
Licensing
Klocwork supports Reprise License Manager (RLM).
- 2025 licenses are not compatible with Klocwork2026.1 or newer. To use the latest version of the product, obtain a new license by contacting license@perforce.com. For more information, see Supported versions of RLM and Operating systems that support RLM dongles.
- The RLM command line utility
rlmstatcan be installed from the Validate or RLM license server package.
Changes to system requirements
Added support for the following environments:
- Amazon Linux 2023
- Apache Commons Bean Utilities 1.11.0
- Apache Derby 10.14.2.0
- Apache log4j 2.26.1
- Apache Tomcat 10.1.59
- Bouncy Castle 1.85
- CLion 2025.2 (up to 2025.2.6.2), 2025.3 (up to 2025.3.6.1), 2026.1 (up to 2026.1.5)
- Eclipse 4.2 (Juno) to 4.37 (2025-09)
- ESLint 8.57.1
- Expat 2.8.2
- glibc 2.27 to 2.44
- Google Chrome 140.x to 152.x
- gradle/gradlew 3.x to 9.7.1
- Guava 32.0.1
- jackson-databind 2.21.5
- jakarta.servlet-api 6.0.0
- JetBrains IntelliJ IDEA 2025.3 (up to 2025.3.6.1)
- Jetty 12.1.10
- JQuery 3.7.1
- jsoup 1.23.1
- Logback 1.5.38
- Maven Plugin API 3.8.1
- MCP SDK 1.1.3
- Microsoft Edge 140.x to 151.x
- Mozilla Firefox 143.x to 154.x
- Node.js 16.20.2
- OpenJDK JRE 17.0.20_8
- OpenSSL 3.5.7
- Oracle Linux 9.8
- Plexus 4.0.3
- Spring AI 1.1.8
- Spring Boot 3.5.16
- SQLite 3.53.2
- Visual Studio 2017 (up to 15.9.82), 2019 (up to 16.11.59), 2022 (up to 17.14.39)
- Xerces 2.12.2
Ended support for the following environments:
-
AlmaLinux 9 to 9.8, 10 to 10.2
-
Amazon Linux 2
-
Apache Commons Bean Utilities 1.9.4
-
Apache Derby 10.10.1.1
-
Apache log4j 2.25.4
-
Apache Tomcat 10.1.49
-
Debian 11.0 to 11.11
-
ESLint 8.20
-
Expat 2.2.9
-
Fedora 42
-
Google Chrome 137.x to 139.x
-
Guava 31.1
-
Microsoft Edge 137.x to 139.x
-
Mozilla Firefox 140.x to 142.x
-
Node.js 16.16.0
-
OpenJDK JRE 1.8.0.372
-
OpenSSL 1.1.1c
-
SQLite 3.8.6
-
Ubuntu 18.04 to 18.04.6 LTS, 20.04 to 20.04.6 LTS
-
VS Code 1.101.2 to 1.104.2
For the complete list of supported versions, see the System Requirements.
Deprecations
-
Release
2026.3+: The bundled_jvmfolder is planned for removal in2026.4. SetKW_JAVAorJAVA_HOMEso that your configuration continues to work after you upgrade. -
Release
2026.3+: Support for Amazon Linux 2 ended in 2026.2 and has been removed from 2026.3. Amazon Linux 2023 is now supported. -
Release
2026.2+: Support for Structure101 ended in 2024.3 and will be removed in a future release. -
Release
2026.1+: The hybrid analysis engine has been removed from the Klocwork plugin for Visual Studio. -
Release
2025.4+: The Klocwork Static Analysis plugin for Visual Studio is no longer provided or supported for Visual Studio 2015 in alignment with Microsoft's end of extended support for Visual Studio 2015.