https://seclists.org/oss-sec/2026/q3/615: CVE-2026-70449: Apache Wicket: Path traversal in source style/variation/locale
Published Aug 30, 2026
·Updated
Affected Software
3 affected components
Apache wicket>=8.0.0<=8.18.0
Apache wicket>=9.0.0<=9.23.0
Apache wicket>=10.0.0<=10.10.0
Frequently Asked Questions
1
Which deployments are exposed?
Deployments using wicket-core 8.0.0 through 8.18.0, 9.0.0 through 9.23.0, or 10.0.0 through 10.10.0 are affected. Exploitation depends on the servlet container normalizing .. sequences in ServletContext.getResource().
2
What does an attacker need to exploit this issue?
An attacker can be unauthenticated and remote. They need to send a crafted package-resource request whose locale, style, or variation attribute introduces path separators into the resource lookup path.
3
What files could be exposed?
The issue can allow reading files from the web application, including files beneath WEB-INF that the servlet container would not normally serve. Disclosure is limited to file extensions permitted by the configured IPackageResourceGuard.