{"id":"CVE-2026-105111","title":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL.\n\n\n\nThis only happens when you're using Class2HTML to generate webpages for possibly-attacker-controlled class file…","summary":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL.\n\n\n\nThis only happens when you're using Class2HTML to generate webpages for possibly-attacker-controlled class file…","severity":"medium","cvss":4.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"Apache Software Foundation","product":"org.apache.bcel:bcel","affected":["org.apache.bcel:bcel < 6.13.0","org.apache.bcel:bcel < fb72c225cbc6ec3d94060ed6edb269f07428d504"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T20:17:15.463","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105111","references":[{"url":"https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504.patch","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/co1wfk2lyrmpnfhn49o370pvfl978rw6","label":"security@apache.org"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-06T19:58:48.850537Z"},"ingestedAt":"2026-10-06T20:16:42.468Z","slug":"CVE-2026-105111","body":"## Overview\n\nImproper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL.\n\n\n\nThis only happens when you're using Class2HTML to generate webpages for possibly-attacker-controlled class files, where Class2HTML emitters write attacker class-file strings into HTML unescaped (stored XSS in reports).\n\n\n\nThis issue affects Apache Commons BCEL: before 6.13.0.\n\n\n\nUsers are recommended to upgrade to version 6.13.0, which fixes the issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":25.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}