Bug 2547113 (CVE-2026-105111) - CVE-2026-105111 org.apache.bcel/bcel: Apache Commons BCEL: Stored Cross-Site Scripting via untrusted class files in Class2HTML
Summary: CVE-2026-105111 org.apache.bcel/bcel: Apache Commons BCEL: Stored Cross-Site ...
Keywords:
Status: NEW
Alias: CVE-2026-105111
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2547327 2547329 2547331 2547333 2547328 2547330 2547332
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-06 19:54 UTC by OSIDB Bzimport
Modified: 2026-10-07 10:48 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-06 19:54:12 UTC
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL.



This only happens when you're using Class2HTML to generate webpages for possibly-attacker-controlled class files, where Class2HTML emitters write attacker class-file strings into HTML unescaped (stored XSS in reports).



This issue affects Apache Commons BCEL: before 6.13.0.



Users are recommended to upgrade to version 6.13.0, which fixes the issue.


Note You need to log in before you can comment on or make changes to this bug.