CVE-2026-105111

Source
https://cve.org/CVERecord?id=CVE-2026-105111
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105111.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105111
Downstream
Related
Published
2026-10-06T19:44:18Z
Modified
2026-10-09T17:26:55Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling stored XSS
Details

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL.

This only happens when you're using Class2HTML to generate webpages for possibly-attacker-controlled class files, where Class2HTML emitters write attacker class-file strings into HTML unescaped (stored XSS in reports).

This issue affects Apache Commons BCEL: before 6.13.0.

Users are recommended to upgrade to version 6.13.0, which fixes the issue.

Database specific
{
    "cna_assigner": "apache",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105111.json"
}
References

Affected packages

Git / gitbox.apache.org/repos/asf/commons-bcel.git

Affected ranges

Type
GIT
Repo
https://gitbox.apache.org/repos/asf/commons-bcel.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
fb72c225cbc6ec3d94060ed6edb269f07428d504
Type
GIT
Repo
https://github.com/apache/commons-bcel
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "6.13.0"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

commons-bcel-6.*
commons-bcel-6.3.1
commons-bcel-6.3.1-RC1
commons-bcel-6.4.0-RC1
commons-bcel-6.4.0-RC2
commons-bcel-6.4.1-RC1
commons-bcel-6.5.0-RC1
commons-bcel-6.6.0-RC1
commons-bcel-6.8.0-RC1
commons-bcel-6.8.1-RC1
rel/commons-bcel-6.*
rel/commons-bcel-6.4.0
rel/commons-bcel-6.4.1
rel/commons-bcel-6.5.0
rel/commons-bcel-6.6.0
rel/commons-bcel-6.8.0
rel/commons-bcel-6.8.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105111.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "326763463435560253468034361808780896131",
            "length": 998
        },
        "id": "CVE-2026-105111-0230494d",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://gitbox.apache.org/repos/asf/commons-bcel.git@fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/MethodHTML.java",
            "function": "writeField"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "102166359680356773874044976360179276733",
            "length": 5243
        },
        "id": "CVE-2026-105111-071ca3a1",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/ConstantHTML.java",
            "function": "writeConstant"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "55328601519474346378269817497251330189",
            "length": 1865
        },
        "id": "CVE-2026-105111-0cb4b90a",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://gitbox.apache.org/repos/asf/commons-bcel.git@fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/MethodHTML.java",
            "function": "writeMethod"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "246737784068709867689392001224969396451",
                "102417088336958536661237791077745312979",
                "332766928815090860661876436301382680206",
                "204923748217826683585174340911669928324",
                "217748784823748562789462960041273842837",
                "141838486536023333662484658755018781767",
                "220153607111190258030848993580483389137",
                "151461097413735256047066549769621423259",
                "276204812965403557920909344781926845054",
                "162126202498838470203193371064762120603",
                "33833665756271908604716393422274061475",
                "117562790858737561342304950389387832981",
                "150132404496800494234682555510452664714",
                "192243693333491500882538099033887424134"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-105111-121b8ff4",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://gitbox.apache.org/repos/asf/commons-bcel.git@fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/Class2HTML.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "102166359680356773874044976360179276733",
            "length": 5243
        },
        "id": "CVE-2026-105111-121e69c1",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://gitbox.apache.org/repos/asf/commons-bcel.git@fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/ConstantHTML.java",
            "function": "writeConstant"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "262610257031764994041091045251692759574",
                "171393737718853338107263010907724618207",
                "99756512033697226030295733703638960496",
                "252895594134630429524791317746432731335"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-105111-3addd58c",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/CodeHTML.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "145928049342105337108266718080442416223",
                "85786969405755020778471729088107978746"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-105111-47050d21",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/test/java/org/apache/bcel/util/Class2HTMLXSSTest.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "317092009247675207656316651811696448725",
                "150559804261760797370329865374132179709",
                "153204816056102220572775991786824056279",
                "127772943320775764918024350787191150394",
                "2692614902117793886664974994055975831",
                "338893028188942052435172942467895356476",
                "225505085448242297083817493800108228284",
                "30537075721427850024388246090371266333",
                "316317317673241791516604095960112047369",
                "251899689894133370337094176702828487050",
                "188469336330839277385609893830459782443",
                "306970416209778452426731356003855730623"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-105111-471146c9",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/MethodHTML.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "145928049342105337108266718080442416223",
                "85786969405755020778471729088107978746"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-105111-48ca2829",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://gitbox.apache.org/repos/asf/commons-bcel.git@fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/test/java/org/apache/bcel/util/Class2HTMLXSSTest.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "277339837409611992417107106867092807545",
            "length": 9174
        },
        "id": "CVE-2026-105111-606e207e",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://gitbox.apache.org/repos/asf/commons-bcel.git@fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/CodeHTML.java",
            "function": "codeToHTML"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "203866820074141232392721418387227447593",
                "7666763342247812475413612258738203723",
                "118081033196207647289413064766007913882",
                "142221628666471802938396895651909420508",
                "286376523162716129750727641820629286261",
                "34218736699715163802628254982951283260",
                "96170156681267877429809734869896109565",
                "11279565312462125661080609579014012914",
                "278748797035141246963926197471535465647",
                "136151713364699095650371436300263189164",
                "177192799614865949825105928421878163635",
                "78979736271002659801002331816602552007",
                "182314925989612739855549432483083248602",
                "209277623120944387609627920834029009481"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-105111-7521849d",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://gitbox.apache.org/repos/asf/commons-bcel.git@fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/ConstantHTML.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "204705887809301787245737958603979191367",
            "length": 447
        },
        "id": "CVE-2026-105111-911686ae",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://gitbox.apache.org/repos/asf/commons-bcel.git@fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/Class2HTML.java",
            "function": "referenceType"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "277339837409611992417107106867092807545",
            "length": 9174
        },
        "id": "CVE-2026-105111-91be624c",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/CodeHTML.java",
            "function": "codeToHTML"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "88446034129442143867015411049593817693",
            "length": 453
        },
        "id": "CVE-2026-105111-a6b34c5a",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/Class2HTML.java",
            "function": "toHTML"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "317092009247675207656316651811696448725",
                "150559804261760797370329865374132179709",
                "153204816056102220572775991786824056279",
                "127772943320775764918024350787191150394",
                "2692614902117793886664974994055975831",
                "338893028188942052435172942467895356476",
                "225505085448242297083817493800108228284",
                "30537075721427850024388246090371266333",
                "316317317673241791516604095960112047369",
                "251899689894133370337094176702828487050",
                "188469336330839277385609893830459782443",
                "306970416209778452426731356003855730623"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-105111-aac8fb86",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://gitbox.apache.org/repos/asf/commons-bcel.git@fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/MethodHTML.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "226907598356993166384295375483405615976",
                "274301446251762422415392824580175349052",
                "210831633171073621393554960191410782602",
                "238029531524346651707596438964609001658",
                "226981035551455322130644609679595934425",
                "208476283131738943725747342582302771134",
                "226274668091310747055030864321792227363",
                "180323139516738842111097830446942104586"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-105111-aae04f16",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/AttributeHTML.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "246737784068709867689392001224969396451",
                "102417088336958536661237791077745312979",
                "332766928815090860661876436301382680206",
                "204923748217826683585174340911669928324",
                "217748784823748562789462960041273842837",
                "141838486536023333662484658755018781767",
                "220153607111190258030848993580483389137",
                "151461097413735256047066549769621423259",
                "276204812965403557920909344781926845054",
                "162126202498838470203193371064762120603",
                "33833665756271908604716393422274061475",
                "117562790858737561342304950389387832981",
                "150132404496800494234682555510452664714",
                "192243693333491500882538099033887424134"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-105111-ba305837",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/Class2HTML.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "55328601519474346378269817497251330189",
            "length": 1865
        },
        "id": "CVE-2026-105111-c2d226da",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/MethodHTML.java",
            "function": "writeMethod"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "326763463435560253468034361808780896131",
            "length": 998
        },
        "id": "CVE-2026-105111-c58c3390",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/MethodHTML.java",
            "function": "writeField"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "203866820074141232392721418387227447593",
                "7666763342247812475413612258738203723",
                "118081033196207647289413064766007913882",
                "142221628666471802938396895651909420508",
                "286376523162716129750727641820629286261",
                "34218736699715163802628254982951283260",
                "96170156681267877429809734869896109565",
                "11279565312462125661080609579014012914",
                "278748797035141246963926197471535465647",
                "136151713364699095650371436300263189164",
                "177192799614865949825105928421878163635",
                "78979736271002659801002331816602552007",
                "182314925989612739855549432483083248602",
                "209277623120944387609627920834029009481"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-105111-d0e49443",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/ConstantHTML.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "88446034129442143867015411049593817693",
            "length": 453
        },
        "id": "CVE-2026-105111-e47e97de",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://gitbox.apache.org/repos/asf/commons-bcel.git@fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/Class2HTML.java",
            "function": "toHTML"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "142638057676887256183678044432269003404",
            "length": 4294
        },
        "id": "CVE-2026-105111-e78fe0d2",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/AttributeHTML.java",
            "function": "writeAttribute"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "226907598356993166384295375483405615976",
                "274301446251762422415392824580175349052",
                "210831633171073621393554960191410782602",
                "238029531524346651707596438964609001658",
                "226981035551455322130644609679595934425",
                "208476283131738943725747342582302771134",
                "226274668091310747055030864321792227363",
                "180323139516738842111097830446942104586"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-105111-eb991e0d",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://gitbox.apache.org/repos/asf/commons-bcel.git@fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/AttributeHTML.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "142638057676887256183678044432269003404",
            "length": 4294
        },
        "id": "CVE-2026-105111-ef2def88",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://gitbox.apache.org/repos/asf/commons-bcel.git@fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/AttributeHTML.java",
            "function": "writeAttribute"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "262610257031764994041091045251692759574",
                "171393737718853338107263010907724618207",
                "99756512033697226030295733703638960496",
                "252895594134630429524791317746432731335"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-105111-f5720319",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://gitbox.apache.org/repos/asf/commons-bcel.git@fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/CodeHTML.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "204705887809301787245737958603979191367",
            "length": 447
        },
        "id": "CVE-2026-105111-f7cee14a",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504",
        "target": {
            "file": "src/main/java/org/apache/bcel/util/Class2HTML.java",
            "function": "referenceType"
        }
    }
]
vanir_signatures_modified
"2026-10-09T07:06:22Z"