CVE-2026-61899: Apache Tapestry: Possible classpath file download through URL manipulation
Published Aug 10, 2026
·Updated
Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Users are recommended to upgrade to version 5.9.1, which fixes this issue.
Affected Software
1 affected component
Apache Apache Tapestry>=5.5.0<5.9.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tapestryto a version that resolves this vulnerability.Fixed in 5.9.1
Event History
Aug 10, 2026
CVE Published
via MITRE·10:36 AM
Data Sourced
via MITRE·10:36 AM
DescriptionWeakness
Data Sourced
via NVD·11:17 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-61899?
The severity of CVE-2026-61899 is rated as risk 48.
2
How do I fix CVE-2026-61899?
To fix CVE-2026-61899, users are recommended to upgrade to Apache Tapestry version 5.9.1.
3
What does CVE-2026-61899 affect?
CVE-2026-61899 affects the tapestry-core component of Apache Tapestry versions 5.5.0 and later.
4
What type of vulnerability is CVE-2026-61899?
CVE-2026-61899 is classified as an information leak vulnerability.
5
What can attackers do with CVE-2026-61899?
Attackers can exploit CVE-2026-61899 to download classpath assets by manipulating URLs.