Path Traversal Vulnerability in Apache Tapestry 5.5.0+
CVE-2026-61899
7.5HIGH
What is CVE-2026-61899?
A path traversal vulnerability exists in the Apache Tapestry framework versions 5.5.0 and above, which allows malicious actors to craft URLs that can download classpath assets. This poses a significant risk as it may enable unauthorized access to sensitive information stored on the server. Users are strongly advised to upgrade to version 5.9.1 to resolve this issue and safeguard their applications.
Affected Version(s)
Apache Tapestry 5.5.0 < 5.9.1