#1150227 bcel: CVE-2026-105111

Package:
src:bcel
Source:
src:bcel
Submitter:
Salvatore Bonaccorso
Date:
2026-10-07 11:39:03 UTC
Severity:
normal
Tags:
#1150227#5
Date:
2026-10-07 11:37:21 UTC
From:
To:
Hi,

The following vulnerability was published for bcel.

CVE-2026-105111[0]:
| Improper neutralization of input during web page generation ('cross-
| site scripting') vulnerability in Apache Commons BCEL.    This only
| happens when you're using Class2HTML to generate webpages for
| possibly-attacker-controlled class files, where Class2HTML emitters
| write attacker class-file strings into HTML unescaped (stored XSS in
| reports).    This issue affects Apache Commons BCEL: before 6.13.0.
| Users are recommended to upgrade to version 6.13.0, which fixes the
| issue.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-105111
https://www.cve.org/CVERecord?id=CVE-2026-105111
[1] https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504
[2] https://lists.apache.org/thread/co1wfk2lyrmpnfhn49o370pvfl978rw6

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore