← Back to CVE List
CVE-2026-105111NVD
Vulnerability Summary
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL.
This only happens when you're using Class2HTML to generate webpages for possibly-attacker-controlled class files, where Class2HTML emitters write attacker class-file strings into HTML unescaped (stored XSS in reports).
This issue affects Apache Commons BCEL: before 6.13.0.
Users are recommended to upgrade to version 6.13.0, which fixes the issue.
This only happens when you're using Class2HTML to generate webpages for possibly-attacker-controlled class files, where Class2HTML emitters write attacker class-file strings into HTML unescaped (stored XSS in reports).
This issue affects Apache Commons BCEL: before 6.13.0.
Users are recommended to upgrade to version 6.13.0, which fixes the issue.
CVSS v4.0 Base Metrics — Score 2.3 (LOW)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsPresent
Privileges RequiredNone
User InteractionPassive
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)None
Confidentiality (Subsequent System)Low
Integrity (Subsequent System)Low
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 4.7 (MEDIUM)
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionRequired
ScopeChanged
ConfidentialityLow
IntegrityLow
AvailabilityNone
Affected & Patched Versions
- Apache Software Foundation Apache Commons BCEL < 6.13.0
- Apache Software Foundation Apache Commons BCEL < fb72c225cbc6ec3d94060ed6edb269f07428d504
- Apache Software Foundation Apache Commons BCEL 6.13.0
- Apache Software Foundation Apache Commons BCEL fb72c225cbc6ec3d94060ed6edb269f07428d504