CVE-2026-76983: Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel
Improper neutralization of input during web page generation in Apache Wicket.
The <wicket:label> tag is provided by org.apache.wicket.markup.html.form.AutoLabelTextResolver, which is registered by default in every WebApplication. The resolver writes the label it finds into the markup as it is, and reads no escaping setting at all, so markup in a label is rendered as markup.
When the label comes from the labelled component's label model, set through FormComponent#setLabel(IModel), it is written to the markup unescaped. An application is affected where the label of a form component holds data an attacker can influence. Wicket cannot determine where a model value comes from, so whether it reaches the page from a request or from storage is a property of the application.
There is no workaround. Unlike every other rendering path in Wicket, the resolver never consulted the escape-model-strings setting, so an application had no way to ask for the label to be escaped.
The body of a <wicket:label> tag is markup by design and is not affected; it remains the supported way to place markup in a label.
This issue affects Apache Wicket: from 8.0.0 through 8.18.0, from 9.0.0 through 9.23.0, from 10.0.0 through 10.10.0. Older, unsupported releases from 1.5.0 onwards are also affected. Users are recommended to upgrade to version 8.19.0, 9.24.0 or 10.11.0, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Wicketto a version that resolves this vulnerability.Fixed in 8.19.0 - Upgrade
Upgrade
Apache Wicketto a version that resolves this vulnerability.Fixed in 9.24.0 - Upgrade
Upgrade
Apache Wicketto a version that resolves this vulnerability.Fixed in 10.11.0 - Compensating control
No workaround is available; mitigate by upgrading Apache Wicket as specified.
Event History
Frequently Asked Questions
Are applications affected by default?
The AutoLabelTextResolver that handles <wicket:label> is registered by default in every WebApplication. An application is affected if a form component's label model, supplied through FormComponent#setLabel(IModel), can contain attacker-influenced data.
What must an attacker be able to control?
An attacker needs to influence the value held in a labelled form component's label model. That value may originate from a request or from stored data; Wicket cannot determine the source of a model value.
Can the escape-model-strings setting mitigate this issue?
No. This resolver does not consult the escape-model-strings setting, so applications cannot configure label-model output to be escaped through that setting.
Is there a workaround if patching is not immediately possible?
No workaround is provided. Applications should identify form labels set through FormComponent#setLabel(IModel) and determine whether their model values can be influenced by untrusted input.
Does this affect markup placed directly in the body of a <wicket:label> tag?
No. The body of a <wicket:label> tag is intentionally treated as markup and is not affected; it remains the supported mechanism for placing markup in a label.