Hi,
The following vulnerability was published for bcel.
CVE-2026-105111[0]:
| Improper neutralization of input during web page generation ('cross-
| site scripting') vulnerability in Apache Commons BCEL. This only
| happens when you're using Class2HTML to generate webpages for
| possibly-attacker-controlled class files, where Class2HTML emitters
| write attacker class-file strings into HTML unescaped (stored XSS in
| reports). This issue affects Apache Commons BCEL: before 6.13.0.
| Users are recommended to upgrade to version 6.13.0, which fixes the
| issue.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-105111
https://www.cve.org/CVERecord?id=CVE-2026-105111
[1] https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504
[2] https://lists.apache.org/thread/co1wfk2lyrmpnfhn49o370pvfl978rw6
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore