CVE-2026-43646: Apache Wicket: crafted URLs can bypass PackageResourceGuard
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket.
This issue affects Apache Wicket: from 8.0.0 through 8.17.0, from 9.0.0 through 9.22.0, from 10.0.0 through 10.8.0.
Users are recommended to upgrade to version 10.9.0, which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43646?
CVE-2026-43646 has been classified as a moderate severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2026-43646?
To fix CVE-2026-43646, upgrade Apache Wicket to versions 8.17.1, 9.22.1, or 10.8.1 or later.
What versions of Apache Wicket are affected by CVE-2026-43646?
CVE-2026-43646 affects Apache Wicket versions 8.0.0 through 8.17.0, 9.0.0 through 9.22.0, and 10.0.0 through 10.8.0.
What type of vulnerability is CVE-2026-43646?
CVE-2026-43646 is a vulnerability that allows crafted URLs to bypass PackageResourceGuard, potentially exposing sensitive information.
Who is impacted by CVE-2026-43646?
Users running affected versions of Apache Wicket are at risk of sensitive information exposure due to CVE-2026-43646.