Advisory CVE-2026-105111 describes improper neutralization of input during web page generation, a stored cross-site scripting issue, in Apache Commons BCEL's Class2HTML. The tool produces HTML pages with unescaped class strings, which may allow script execution in the browser of whoever opens the generated page. According to the text, versions before 6.13.0 are affected, as are versions before commit fb72c225cbc6ec3d94060ed6edb269f07428d504.
The advisory was published by Gary D. Gregory on October 6 on the oss-sec list and is rated low severity. The CVSS 3.1 score is 4.7 (medium), with network attack vector, high complexity, user interaction required and changed scope. The CVSS 4.0 score is 2.3 (low). The text states that the content was machine-translated from the original feed.
To verify the details, consult the original message in the oss-sec list archive for the fourth quarter of 2026, searching by the advisory title. Practical relevance: if your organization uses BCEL in internal tools that generate HTML reports, check the installed version and consider upgrading to 6.13.0 or later. Treat generated pages as untrusted content.
Rota Nacional does not patch third-party libraries, and this text does not attribute any platform capability to this flaw. If your team uses AI to study the advisory, do not paste logs, user names or internal data without treatment: the platform detects personal data before any model runs and applies the policy configured by the organization.