Bug 2547331 - CVE-2026-105111 rubygem-nokogiri: Apache Commons BCEL: Stored Cross-Site Scripting via untrusted class files in Class2HTML [epel-all]
Summary: CVE-2026-105111 rubygem-nokogiri: Apache Commons BCEL: Stored Cross-Site Scri...
Keywords:
Status: NEW
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: rubygem-nokogiri
Version: epel10
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Troy Dawson
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["95693737-a976-4883-b709-6...
Depends On:
Blocks: CVE-2026-105111
TreeView+ depends on / blocked
 
Reported: 2026-10-07 09:12 UTC by Ronit Dey
Modified: 2026-10-07 09:12 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ronit Dey 2026-10-07 09:12:33 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL.



This only happens when you're using Class2HTML to generate webpages for possibly-attacker-controlled class files, where Class2HTML emitters write attacker class-file strings into HTML unescaped (stored XSS in reports).



This issue affects Apache Commons BCEL: before 6.13.0.



Users are recommended to upgrade to version 6.13.0, which fixes the issue.


Note You need to log in before you can comment on or make changes to this bug.