org.apache.bcel:bcel vulnerabilities
CVEs whose affected-version data names the org.apache.bcel:bcel package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-105111Medium· 4.7Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL. This only happens when you're using Class2HTML to generate webpages for possibly-attacker-controlled class file…
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL. This only happens when you're using Class2HTML to generate webpages for possibly-attacker-controlled class file…
▾ SunlitApache Software Foundation · org.apache.bcel:bcelvia NVD
CVE-2026-94114Medium· 5.9Symbolic name not mapping to correct object vulnerability in Apache Commons. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed ver…
Symbolic name not mapping to correct object vulnerability in Apache Commons. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed ver…
▾ SunlitApache Software Foundation · org.apache.bcel:bcelvia NVD