Cross-Site Request Forgery Vulnerability in Apache Wicket by Apache
CVE-2026-71378
Currently unrated
What is CVE-2026-71378?
A security vulnerability in Apache Wicket exposes applications to cross-site request forgery attacks due to improper handling of resource isolation policies. The FetchMetadataResourceIsolationPolicy allows GET requests under conditions that may include unsafe top-level navigations and same-site requests. Consequently, an attacker can exploit this flaw to execute unauthorized actions within a victim's authenticated session, potentially compromising sensitive data. To mitigate the risk, users are advised to upgrade to Apache Wicket version 9.24.0 or 10.11.0.
Affected Version(s)
Apache Wicket 9.1.0 <= 9.23.0
Apache Wicket 10.0.0 <= 10.10.0