Cross-Site Request Forgery Vulnerability in Apache Wicket by Apache
CVE-2026-71378

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
31 August 2026

What is CVE-2026-71378?

A security vulnerability in Apache Wicket exposes applications to cross-site request forgery attacks due to improper handling of resource isolation policies. The FetchMetadataResourceIsolationPolicy allows GET requests under conditions that may include unsafe top-level navigations and same-site requests. Consequently, an attacker can exploit this flaw to execute unauthorized actions within a victim's authenticated session, potentially compromising sensitive data. To mitigate the risk, users are advised to upgrade to Apache Wicket version 9.24.0 or 10.11.0.

Affected Version(s)

Apache Wicket 9.1.0 <= 9.23.0

Apache Wicket 10.0.0 <= 10.10.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Darren Carreras
Andre Kropp (Nexory)
.