CVE-2026-61899
Apache Tapestry: Possible classpath file download through URL manipulation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Users are recommended to upgrade to version 5.9.1, which fixes this issue.
| CWE | CWE-200 |
| Vendor | apache software foundation |
| Product | apache tapestry |
| Published | Aug 10, 2026 |
| Last Updated | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache tapestry
Be the first to know when new unknown vulnerabilities affecting apache software foundation apache tapestry are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Apache Software Foundation / Apache Tapestry
5.5.0 < 5.9.1
References
Credits
Ilyass El Hadi