CVE-2026-61899

Source
https://cve.org/CVERecord?id=CVE-2026-61899
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61899.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-61899
Published
2026-08-10T10:36:03.160Z
Modified
2026-08-20T10:17:18.514985Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Apache Tapestry: Possible classpath file download through URL manipulation
Details

Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Users are recommended to upgrade to version 5.9.1, which fixes this issue.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "5.5.0"
                },
                {
                    "fixed": "5.9.1"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cna_assigner": "apache",
    "cwe_ids": [
        "CWE-200"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61899.json"
}
References

Affected packages

Git / github.com/apache/tapestry-5

Affected ranges

Type
GIT
Repo
https://github.com/apache/tapestry-5
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "5.5.0"
        },
        {
            "fixed": "5.9.1"
        }
    ],
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:apache:tapestry:*:*:*:*:*:*:*:*"
}

Affected versions

5.*
5.5.0
5.6.0
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.9.0
5.9.0-preview
5.9.0-preview-2
Other
pre-jakarta-ee

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61899.json"
vanir_signatures
[
    {
        "target": {
            "function": "getModel",
            "file": "tapestry-core/src/main/java/org/apache/tapestry5/internal/services/ComponentModelSourceImpl.java"
        },
        "deprecated": false,
        "source": "https://github.com/apache/tapestry-5/commit/6b58f74daa8668e590f645b2b83c866da273e009",
        "id": "CVE-2026-61899-23aa5ee5",
        "signature_version": "v1",
        "digest": {
            "length": 476.0,
            "function_hash": "113921331262514404480959009764485269107"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "function": "toJSONObject",
            "file": "tapestry-core/src/main/java/org/apache/tapestry5/internal/transform/CachedWorker.java"
        },
        "deprecated": false,
        "source": "https://github.com/apache/tapestry-5/commit/6b58f74daa8668e590f645b2b83c866da273e009",
        "id": "CVE-2026-61899-7c9ad8a4",
        "signature_version": "v1",
        "digest": {
            "length": 419.0,
            "function_hash": "104604372427112265623850376465829775375"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "tapestry-core/src/main/java/org/apache/tapestry5/internal/services/ComponentModelSourceImpl.java"
        },
        "deprecated": false,
        "source": "https://github.com/apache/tapestry-5/commit/6b58f74daa8668e590f645b2b83c866da273e009",
        "id": "CVE-2026-61899-8e6aaedd",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "137517030246639215210157868212458837008",
                "6839652970917183621448163248224269813",
                "333213982870976626490792619251670071349",
                "70715776689004655938781492084357440256",
                "260823335763592960698788159217529254556",
                "222312868174399554430769332960648003950",
                "238289240434603366856860913819942502306",
                "244167038459064932821863484608671839581",
                "107360253771376253666997579555382431542",
                "228570556232123837238848395355091777971",
                "129294484817066844466049668363745753300",
                "131607563087873323869102289966021514890",
                "321272545195853111637681372448510104856",
                "312513782732803694175286784836948930124",
                "52303561012946468298491029271215934898",
                "155905722199831719453760158291473616166",
                "304167992807647103520053699090167119689",
                "186566208900995943280856580835431136247",
                "108587633537507210242609878158511307392"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "tapestry-core/src/test/java/org/apache/tapestry5/integration/app1/CacheTests.java"
        },
        "deprecated": false,
        "source": "https://github.com/apache/tapestry-5/commit/6b58f74daa8668e590f645b2b83c866da273e009",
        "id": "CVE-2026-61899-a9afa729",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "147650077791964462503090760683419871804",
                "321411760906575048959957101034250134570"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "tapestry-core/src/main/java/org/apache/tapestry5/internal/transform/CachedWorker.java"
        },
        "deprecated": false,
        "source": "https://github.com/apache/tapestry-5/commit/6b58f74daa8668e590f645b2b83c866da273e009",
        "id": "CVE-2026-61899-c81f9873",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "6540567895529673483690722780838411755",
                "226733109382285939043142189650162805949",
                "281482149044735956795474581130983971414",
                "94770001629875437212343540072548561275",
                "134407262616141734223337291968842208768",
                "298055879333367658557569946735176072866",
                "210921492935543603440602169257118546328",
                "57755939545151148009885084093090571532",
                "52197749969099207343387467969348653784"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "tapestry-core/src/test/java/org/apache/tapestry5/integration/app1/pages/Index.java"
        },
        "deprecated": false,
        "source": "https://github.com/apache/tapestry-5/commit/6b58f74daa8668e590f645b2b83c866da273e009",
        "id": "CVE-2026-61899-dd67cc76",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "221389370459541310429415030876937229908",
                "254575959544664122688762453977417508098",
                "161138589539862284574362943797446021856",
                "76820706862145459399099202330568708086"
            ]
        },
        "signature_type": "Line"
    }
]
vanir_signatures_modified
"2026-08-20T10:17:18Z"