Apache Commons BCEL 中在生成网页时存在不恰当的对输入进行中性化处理(即“跨站脚本攻击”,XSS)的漏洞。 该问题仅在使用 Class2HTML 为可能由攻击者控制的类文件生成网页时发生。Class2HTML 的 emitter 组件将攻击者提供的类文件字符串以未转义的方式直接写入 HTML 中,从而导致存储型 XSS(在报告中出现)。 此漏洞影响 Apache Commons BCEL 6.13.0 之前的版本。 建议用户升级至 6.13.0 版本,该版本已修复此问题。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Commons BCEL | < 6.13.0 |
affected |
< fb72c225cbc6ec3d94060ed6edb269f07428d504 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Commons BCEL | 0 ~ 6.13.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94114 | 5.9 MEDIUM | Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in |
| CVE-2026-105244 | 5.3 MEDIUM | Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content |
| CVE-2026-105243 | 5.3 MEDIUM | Apache log4net: Oversize EventLogAppender record silently discarded |
| CVE-2026-105242 | 5.3 MEDIUM | Apache log4net: Request validation failure drops the event in the aspnet-request converter |
| CVE-2026-105241 | 5.3 MEDIUM | Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch |
| CVE-2026-105240 | 5.3 MEDIUM | Apache log4net: NUL character truncates OutputDebugStringAppender records |
| CVE-2026-105239 | 5.3 MEDIUM | Apache log4net: NUL character truncates EventLogAppender records |
No comments yet