{"record":{"id":"117a942421a79352","repo":"spring-projects/spring-framework","slug":"is-the-constructor-accessible","errorCode":null,"errorMessage":"Is the constructor accessible?","messagePattern":"Is the constructor accessible\\?","errorType":"exception","errorClass":"BeanInstantiationException","httpStatus":null,"severity":"error","filePath":"spring-beans/src/main/java/org/springframework/beans/BeanUtils.java","lineNumber":111,"sourceCode":"\t * @return the new instance\n\t * @throws BeanInstantiationException if the bean cannot be instantiated\n\t * @see Class#newInstance()\n\t * @deprecated following the deprecation of {@link Class#newInstance()} in JDK 9\n\t */\n\t@Deprecated(since = \"5.0\")\n\tpublic static <T> T instantiate(Class<T> clazz) throws BeanInstantiationException {\n\t\tAssert.notNull(clazz, \"Class must not be null\");\n\t\tif (clazz.isInterface()) {\n\t\t\tthrow new BeanInstantiationException(clazz, \"Specified class is an interface\");\n\t\t}\n\t\ttry {\n\t\t\treturn clazz.newInstance();\n\t\t}\n\t\tcatch (InstantiationException ex) {\n\t\t\tthrow new BeanInstantiationException(clazz, \"Is it an abstract class?\", ex);\n\t\t}\n\t\tcatch (IllegalAccessException ex) {\n\t\t\tthrow new BeanInstantiationException(clazz, \"Is the constructor accessible?\", ex);\n\t\t}\n\t}\n\n\t/**\n\t * Instantiate a class using its 'primary' constructor (for Kotlin classes,\n\t * potentially having default arguments declared) or its default constructor\n\t * (for regular Java classes, expecting a standard no-arg setup).\n\t * <p>Note that this method tries to set the constructor accessible\n\t * if given a non-accessible (that is, non-public) constructor.\n\t * @param clazz the class to instantiate\n\t * @return the new instance\n\t * @throws BeanInstantiationException if the bean cannot be instantiated.\n\t * The cause may notably indicate a {@link NoSuchMethodException} if no\n\t * primary/default constructor was found, a {@link NoClassDefFoundError}\n\t * or other {@link LinkageError} in case of an unresolvable class definition\n\t * (for example, due to a missing dependency at runtime), or an exception thrown\n\t * from the constructor invocation itself.\n\t * @see Constructor#newInstance","sourceCodeStart":93,"sourceCodeEnd":129,"githubUrl":"https://github.com/spring-projects/spring-framework/blob/69bf83ad716d0cfc4b0520a19b4d8b24c79d1538/spring-beans/src/main/java/org/springframework/beans/BeanUtils.java#L93-L129","documentation":"Thrown as BeanInstantiationException by the deprecated BeanUtils.instantiate(Class) at BeanUtils.java:111 when Class.newInstance() raises IllegalAccessException — the no-arg constructor exists but is not accessible (non-public and not exported by the module / not accessible to the caller) under the old newInstance() semantics that did not call setAccessible.","triggerScenarios":"Calling deprecated instantiate(Class) for a class whose default constructor is private/protected/package-private, or whose declaring class is non-public in a package not open to the caller (JPMS strong encapsulation). Class.newInstance() does not relax access, unlike instantiateClass which calls makeAccessible.","commonSituations":"Singletons with a private no-arg constructor; classes in another module not 'open' to reflection; JDK 9+ stricter module access hitting legacy code; records/classes in non-public packages.","solutions":["Migrate to BeanUtils.instantiateClass(Class) which calls ReflectionUtils.makeAccessible to relax access.","Make the no-arg constructor public (or at least accessible).","Add 'opens'/'opens ... to' directives so the calling module can access the constructor.","Use the explicit Constructor via instantiateClass(ctor) after makeAccessible yourself."],"exampleFix":"// before (deprecated, fails on private ctor)\nBeanUtils.instantiate(Singleton.class);\n\n// after (relaxes accessibility)\nBeanUtils.instantiateClass(Singleton.class);","handlingStrategy":"fallback","validationCode":"// Prefer the modern API that calls makeAccessible\nBeanUtils.instantiateClass(clazz); // instead of instantiate(clazz)","typeGuard":"static boolean accessibleNoArg(Class<?> c) {\n    try {\n        Constructor<?> k = c.getDeclaredConstructor();\n        return Modifier.isPublic(k.getModifiers()) && Modifier.isPublic(c.getModifiers());\n    } catch (NoSuchMethodException e) { return false; }\n}","tryCatchPattern":"try {\n    BeanUtils.instantiate(clazz);\n} catch (BeanInstantiationException ex) {\n    if (ex.getCause() instanceof IllegalAccessException) {\n        // fall back to API that relaxes access\n        return BeanUtils.instantiateClass(clazz);\n    }\n    throw ex;\n}","preventionTips":["Migrate to instantiateClass(Class) / instantiateClass(Constructor).","Make the no-arg constructor public to avoid accessibility issues.","Add 'opens' directives in module-info for non-public reflective targets.","Avoid the deprecated Class.newInstance()-based path entirely."],"tags":["spring-beans","beanutils","instantiation","accessibility","deprecated","jpms"],"backgroundTag":null,"analyzedSha":"69bf83ad716d0cfc4b0520a19b4d8b24c79d1538","analyzedAt":"2026-08-09T15:32:58.770Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}