CVE-2026-105111
EUVD-2026-9397206.10.2026, 20:17
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL.
This only happens when you're using Class2HTML to generate webpages for possibly-attacker-controlled class files, where Class2HTML emitters write attacker class-file strings into HTML unescaped (stored XSS in reports).
This issue affects Apache Commons BCEL: before 6.13.0.
Users are recommended to upgrade to version 6.13.0, which fixes the issue.Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| apache | commons_bcel | 𝑥 < 6.13.0 | CNA |