Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Users are recommended to upgrade to version 5.9.1, which fixes this issue.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "5.5.0"
},
{
"fixed": "5.9.1"
}
],
"source": "AFFECTED_FIELD"
}
],
"cna_assigner": "apache",
"cwe_ids": [
"CWE-200"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61899.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61899.json"
[
{
"target": {
"function": "getModel",
"file": "tapestry-core/src/main/java/org/apache/tapestry5/internal/services/ComponentModelSourceImpl.java"
},
"deprecated": false,
"source": "https://github.com/apache/tapestry-5/commit/6b58f74daa8668e590f645b2b83c866da273e009",
"id": "CVE-2026-61899-23aa5ee5",
"signature_version": "v1",
"digest": {
"length": 476.0,
"function_hash": "113921331262514404480959009764485269107"
},
"signature_type": "Function"
},
{
"target": {
"function": "toJSONObject",
"file": "tapestry-core/src/main/java/org/apache/tapestry5/internal/transform/CachedWorker.java"
},
"deprecated": false,
"source": "https://github.com/apache/tapestry-5/commit/6b58f74daa8668e590f645b2b83c866da273e009",
"id": "CVE-2026-61899-7c9ad8a4",
"signature_version": "v1",
"digest": {
"length": 419.0,
"function_hash": "104604372427112265623850376465829775375"
},
"signature_type": "Function"
},
{
"target": {
"file": "tapestry-core/src/main/java/org/apache/tapestry5/internal/services/ComponentModelSourceImpl.java"
},
"deprecated": false,
"source": "https://github.com/apache/tapestry-5/commit/6b58f74daa8668e590f645b2b83c866da273e009",
"id": "CVE-2026-61899-8e6aaedd",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"137517030246639215210157868212458837008",
"6839652970917183621448163248224269813",
"333213982870976626490792619251670071349",
"70715776689004655938781492084357440256",
"260823335763592960698788159217529254556",
"222312868174399554430769332960648003950",
"238289240434603366856860913819942502306",
"244167038459064932821863484608671839581",
"107360253771376253666997579555382431542",
"228570556232123837238848395355091777971",
"129294484817066844466049668363745753300",
"131607563087873323869102289966021514890",
"321272545195853111637681372448510104856",
"312513782732803694175286784836948930124",
"52303561012946468298491029271215934898",
"155905722199831719453760158291473616166",
"304167992807647103520053699090167119689",
"186566208900995943280856580835431136247",
"108587633537507210242609878158511307392"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "tapestry-core/src/test/java/org/apache/tapestry5/integration/app1/CacheTests.java"
},
"deprecated": false,
"source": "https://github.com/apache/tapestry-5/commit/6b58f74daa8668e590f645b2b83c866da273e009",
"id": "CVE-2026-61899-a9afa729",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"147650077791964462503090760683419871804",
"321411760906575048959957101034250134570"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "tapestry-core/src/main/java/org/apache/tapestry5/internal/transform/CachedWorker.java"
},
"deprecated": false,
"source": "https://github.com/apache/tapestry-5/commit/6b58f74daa8668e590f645b2b83c866da273e009",
"id": "CVE-2026-61899-c81f9873",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"6540567895529673483690722780838411755",
"226733109382285939043142189650162805949",
"281482149044735956795474581130983971414",
"94770001629875437212343540072548561275",
"134407262616141734223337291968842208768",
"298055879333367658557569946735176072866",
"210921492935543603440602169257118546328",
"57755939545151148009885084093090571532",
"52197749969099207343387467969348653784"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "tapestry-core/src/test/java/org/apache/tapestry5/integration/app1/pages/Index.java"
},
"deprecated": false,
"source": "https://github.com/apache/tapestry-5/commit/6b58f74daa8668e590f645b2b83c866da273e009",
"id": "CVE-2026-61899-dd67cc76",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"221389370459541310429415030876937229908",
"254575959544664122688762453977417508098",
"161138589539862284574362943797446021856",
"76820706862145459399099202330568708086"
]
},
"signature_type": "Line"
}
]
"2026-08-20T10:17:18Z"