Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105111— Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling stored XSS

Quick assessment

Affected
Apache Software Foundation Apache Commons BCEL
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Commons BCEL 中在生成网页时存在不恰当的对输入进行中性化处理(即“跨站脚本攻击”,XSS)的漏洞。 该问题仅在使用 Class2HTML 为可能由攻击者控制的类文件生成网页时发生。Class2HTML 的 emitter 组件将攻击者提供的类文件字符串以未转义的方式直接写入 HTML 中,从而导致存储型 XSS(在报告中出现)。 此漏洞影响 Apache Commons BCEL 6.13.0 之前的版本。 建议用户升级至 6.13.0 版本,该版本已修复此问题。

CVSS 4.7 · Medium

Affected Version Matrix 2

VendorProduct Version RangeStatus
Apache Software Foundation Apache Commons BCEL < 6.13.0 affected
< fb72c225cbc6ec3d94060ed6edb269f07428d504 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105111

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling stored XSS
Source: CVE Program / CVE List V5
Vulnerability Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL. This only happens when you're using Class2HTML to generate webpages for possibly-attacker-controlled class files, where Class2HTML emitters write attacker class-file strings into HTML unescaped (stored XSS in reports). This issue affects Apache Commons BCEL: before 6.13.0. Users are recommended to upgrade to version 6.13.0, which fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Commons BCEL 0 ~ 6.13.0 -

II. Public POCs for CVE-2026-105111

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105111

请登录查看更多情报信息。

Other References for CVE-2026-105111 (2)

Same Patch Batch · Apache Software Foundation · 2026-10-06 · 8 CVEs total

CVE-2026-94114 5.9 MEDIUM Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time recursion in
CVE-2026-105244 5.3 MEDIUM Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content
CVE-2026-105243 5.3 MEDIUM Apache log4net: Oversize EventLogAppender record silently discarded
CVE-2026-105242 5.3 MEDIUM Apache log4net: Request validation failure drops the event in the aspnet-request converter
CVE-2026-105241 5.3 MEDIUM Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch
CVE-2026-105240 5.3 MEDIUM Apache log4net: NUL character truncates OutputDebugStringAppender records
CVE-2026-105239 5.3 MEDIUM Apache log4net: NUL character truncates EventLogAppender records

IV. Related Vulnerabilities

V. Comments for CVE-2026-105111

No comments yet


Leave a comment