Cross-Site Scripting Vulnerability in Apache Commons BCEL
CVE-2026-105111

2.3LOW

Key Information:

Vendor

Apache

Vendor
CVE Published:
6 October 2026

What is CVE-2026-105111?

An input validation issue in Apache Commons BCEL’s Class2HTML tool allows for the improper handling of user-controlled class file strings during the generation of web pages. This vulnerability can lead to stored XSS attacks, where malicious scripts are executed in the context of the victim’s web browser. Users of affected versions should upgrade to version 6.13.0 to address this security issue and prevent potential exploitation.

Affected Version(s)

Apache Commons BCEL 0 < 6.13.0

Apache Commons BCEL 0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Apache Software Foundation
Claude Security
.