Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL.



This only happens when you're using Class2HTML to generate webpages for possibly-attacker-controlled class files, where Class2HTML emitters write attacker class-file strings into HTML unescaped (stored XSS in reports).



This issue affects Apache Commons BCEL: before 6.13.0.



Users are recommended to upgrade to version 6.13.0, which fixes the issue.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 07 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 07 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
References

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL. This only happens when you're using Class2HTML to generate webpages for possibly-attacker-controlled class files, where Class2HTML emitters write attacker class-file strings into HTML unescaped (stored XSS in reports). This issue affects Apache Commons BCEL: before 6.13.0. Users are recommended to upgrade to version 6.13.0, which fixes the issue.
Title Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling stored XSS
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-07T06:11:54.071Z

Reserved: 2026-10-03T12:02:46.675Z

Link: CVE-2026-105111

cve-icon Vulnrichment

Updated: 2026-10-07T06:11:54.071Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T20:17:15.463

Modified: 2026-10-07T13:35:14.410

Link: CVE-2026-105111

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-06T19:44:18Z

Links: CVE-2026-105111 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T01:00:09Z

Weaknesses