What is CVE-2026-61899?
This vulnerability (CVE-2026-61899) in the tapestry-core component of Apache Tapestry 5.5.0+ allows attackers on all platforms to download classpath assets using specially crafted URLs. Users are recommended to upgrade to version 5.9.1 to fix the issue.
Azərbaycanca: Apache Tapestry 5.5.0+ versiyalarında "tapestry-core" komponentində aşkarlanan bu boşluq (CVE-2026-61899) təcavüzkarlara xüsusi hazırlanmış URL-lər vasitəsilə "classpath" aktivlərini yükləməyə imkan verir. İstifadəçilərə problemi aradan qaldırmaq üçün Apache Tapestry 5.9.1 versiyasına yüksəlmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: Apache
FAQ2
Which versions of Apache Tapestry are affected by CVE-2026-61899?
This vulnerability affects Apache Tapestry versions 5.5.0 and later.
Which version should users upgrade to in order to fix CVE-2026-61899?
Users are recommended to upgrade to version 5.9.1 to fix the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.