Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs.
Users are recommended to upgrade to version 5.9.1, which fixes this issue.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/6j3yojqrdsxkrfz52d0zjyrf5n9xttmw | Vendor Advisory Mailing List |
| http://www.openwall.com/lists/oss-security/2026/08/08/2 | Mailing List Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-08-10 11:17
Updated : 2026-08-18 13:23
NVD link : CVE-2026-61899
Mitre link : CVE-2026-61899
CVE.ORG link : CVE-2026-61899
JSON object : View
Products Affected
apache
- tapestry
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
