spring-projects/spring-framework · error · BeanInstantiationException

Is the constructor accessible?

Error message

Is the constructor accessible?

What it means

Thrown as BeanInstantiationException by the deprecated BeanUtils.instantiate(Class) at BeanUtils.java:111 when Class.newInstance() raises IllegalAccessException — the no-arg constructor exists but is not accessible (non-public and not exported by the module / not accessible to the caller) under the old newInstance() semantics that did not call setAccessible.

Solutions

  1. Migrate to BeanUtils.instantiateClass(Class) which calls ReflectionUtils.makeAccessible to relax access.
  2. Make the no-arg constructor public (or at least accessible).
  3. Add 'opens'/'opens ... to' directives so the calling module can access the constructor.
  4. Use the explicit Constructor via instantiateClass(ctor) after makeAccessible yourself.

Example fix

// before (deprecated, fails on private ctor)
BeanUtils.instantiate(Singleton.class);

// after (relaxes accessibility)
BeanUtils.instantiateClass(Singleton.class);
Defensive patterns

Strategy: fallback

Validate before calling

// Prefer the modern API that calls makeAccessible
BeanUtils.instantiateClass(clazz); // instead of instantiate(clazz)

Type guard

static boolean accessibleNoArg(Class<?> c) {
    try {
        Constructor<?> k = c.getDeclaredConstructor();
        return Modifier.isPublic(k.getModifiers()) && Modifier.isPublic(c.getModifiers());
    } catch (NoSuchMethodException e) { return false; }
}

Try / catch

try {
    BeanUtils.instantiate(clazz);
} catch (BeanInstantiationException ex) {
    if (ex.getCause() instanceof IllegalAccessException) {
        // fall back to API that relaxes access
        return BeanUtils.instantiateClass(clazz);
    }
    throw ex;
}

Prevention

When it happens

Trigger: Calling deprecated instantiate(Class) for a class whose default constructor is private/protected/package-private, or whose declaring class is non-public in a package not open to the caller (JPMS strong encapsulation). Class.newInstance() does not relax access, unlike instantiateClass which calls makeAccessible.

Common situations: Singletons with a private no-arg constructor; classes in another module not 'open' to reflection; JDK 9+ stricter module access hitting legacy code; records/classes in non-public packages.

Related errors


AI-assisted analysis of spring-projects/spring-framework@69bf83ad71 (2026-08-09). Data as JSON: /api/errors/117a942421a79352. Report an issue: GitHub.

Appendix: source

Thrown at spring-beans/src/main/java/org/springframework/beans/BeanUtils.java:111

	 * @return the new instance
	 * @throws BeanInstantiationException if the bean cannot be instantiated
	 * @see Class#newInstance()
	 * @deprecated following the deprecation of {@link Class#newInstance()} in JDK 9
	 */
	@Deprecated(since = "5.0")
	public static <T> T instantiate(Class<T> clazz) throws BeanInstantiationException {
		Assert.notNull(clazz, "Class must not be null");
		if (clazz.isInterface()) {
			throw new BeanInstantiationException(clazz, "Specified class is an interface");
		}
		try {
			return clazz.newInstance();
		}
		catch (InstantiationException ex) {
			throw new BeanInstantiationException(clazz, "Is it an abstract class?", ex);
		}
		catch (IllegalAccessException ex) {
			throw new BeanInstantiationException(clazz, "Is the constructor accessible?", ex);
		}
	}

	/**
	 * Instantiate a class using its 'primary' constructor (for Kotlin classes,
	 * potentially having default arguments declared) or its default constructor
	 * (for regular Java classes, expecting a standard no-arg setup).
	 * <p>Note that this method tries to set the constructor accessible
	 * if given a non-accessible (that is, non-public) constructor.
	 * @param clazz the class to instantiate
	 * @return the new instance
	 * @throws BeanInstantiationException if the bean cannot be instantiated.
	 * The cause may notably indicate a {@link NoSuchMethodException} if no
	 * primary/default constructor was found, a {@link NoClassDefFoundError}
	 * or other {@link LinkageError} in case of an unresolvable class definition
	 * (for example, due to a missing dependency at runtime), or an exception thrown
	 * from the constructor invocation itself.
	 * @see Constructor#newInstance

View on GitHub (pinned to 69bf83ad71)