Severity: low
CVSS 3.1: 4.7 (medium) CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS 4.0: 2.3 (low)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected versions:
- Apache Commons BCEL before 6.13.0
- Apache Commons BCEL before fb72c225cbc6ec3d94060ed6edb269f07428d504
Description:
Improper neutralization of input during web page generation ('cross-site
scripting') vulnerability in Apache Commons BCEL.
This only happens when you're using Class2HTML to generate webpages for
possibly-attacker-controlled class files, where Class2HTML emitters write
attacker class-file strings into HTML unescaped (stored XSS in reports).
This issue affects Apache Commons BCEL: before 6.13.0.
Users are recommended to upgrade to version 6.13.0, which fixes the issue.
Credit:
The Apache Software Foundation (finder)
Claude Security (tool)
References:
https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504.patch
https://commons.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-105111