{"id":"CVE-2026-61899","summary":"Apache Tapestry: Possible classpath file download through URL manipulation","details":"Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs.\nUsers are recommended to upgrade to version 5.9.1, which fixes this issue.","modified":"2026-08-20T10:17:18.514985Z","published":"2026-08-10T10:36:03.160Z","database_specific":{"cna_assigner":"apache","cwe_ids":["CWE-200"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61899.json","unresolved_ranges":[{"extracted_events":[{"introduced":"5.5.0"},{"fixed":"5.9.1"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/08/08/2"},{"type":"WEB","url":"https://repo.maven.apache.org/maven2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61899.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/6j3yojqrdsxkrfz52d0zjyrf5n9xttmw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61899"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/tapestry-5","events":[{"introduced":"6076c215068619e8ddefe2beb0e8825790bbaa3f"},{"fixed":"6b58f74daa8668e590f645b2b83c866da273e009"}],"database_specific":{"extracted_events":[{"introduced":"5.5.0"},{"fixed":"5.9.1"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:apache:tapestry:*:*:*:*:*:*:*:*"}}],"versions":["5.9.0","5.9.0-preview-2","5.9.0-preview","pre-jakarta-ee","5.8.4","5.8.3","5.8.2","5.8.1","5.8.0","5.7.3","5.7.2","5.7.1","5.7.0","5.6.0","5.5.0"],"database_specific":{"vanir_signatures_modified":"2026-08-20T10:17:18Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"113921331262514404480959009764485269107","length":476},"id":"CVE-2026-61899-23aa5ee5","signature_type":"Function","signature_version":"v1","source":"https://github.com/apache/tapestry-5/commit/6b58f74daa8668e590f645b2b83c866da273e009","target":{"file":"tapestry-core/src/main/java/org/apache/tapestry5/internal/services/ComponentModelSourceImpl.java","function":"getModel"}},{"id":"CVE-2026-61899-7c9ad8a4","signature_type":"Function","signature_version":"v1","source":"https://github.com/apache/tapestry-5/commit/6b58f74daa8668e590f645b2b83c866da273e009","target":{"file":"tapestry-core/src/main/java/org/apache/tapestry5/internal/transform/CachedWorker.java","function":"toJSONObject"},"deprecated":false,"digest":{"function_hash":"104604372427112265623850376465829775375","length":419}},{"target":{"file":"tapestry-core/src/main/java/org/apache/tapestry5/internal/services/ComponentModelSourceImpl.java"},"deprecated":false,"digest":{"line_hashes":["137517030246639215210157868212458837008","6839652970917183621448163248224269813","333213982870976626490792619251670071349","70715776689004655938781492084357440256","260823335763592960698788159217529254556","222312868174399554430769332960648003950","238289240434603366856860913819942502306","244167038459064932821863484608671839581","107360253771376253666997579555382431542","228570556232123837238848395355091777971","129294484817066844466049668363745753300","131607563087873323869102289966021514890","321272545195853111637681372448510104856","312513782732803694175286784836948930124","52303561012946468298491029271215934898","155905722199831719453760158291473616166","304167992807647103520053699090167119689","186566208900995943280856580835431136247","108587633537507210242609878158511307392"],"threshold":0.9},"id":"CVE-2026-61899-8e6aaedd","signature_type":"Line","signature_version":"v1","source":"https://github.com/apache/tapestry-5/commit/6b58f74daa8668e590f645b2b83c866da273e009"},{"digest":{"line_hashes":["147650077791964462503090760683419871804","321411760906575048959957101034250134570"],"threshold":0.9},"id":"CVE-2026-61899-a9afa729","signature_type":"Line","signature_version":"v1","source":"https://github.com/apache/tapestry-5/commit/6b58f74daa8668e590f645b2b83c866da273e009","target":{"file":"tapestry-core/src/test/java/org/apache/tapestry5/integration/app1/CacheTests.java"},"deprecated":false},{"id":"CVE-2026-61899-c81f9873","signature_type":"Line","signature_version":"v1","source":"https://github.com/apache/tapestry-5/commit/6b58f74daa8668e590f645b2b83c866da273e009","target":{"file":"tapestry-core/src/main/java/org/apache/tapestry5/internal/transform/CachedWorker.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["6540567895529673483690722780838411755","226733109382285939043142189650162805949","281482149044735956795474581130983971414","94770001629875437212343540072548561275","134407262616141734223337291968842208768","298055879333367658557569946735176072866","210921492935543603440602169257118546328","57755939545151148009885084093090571532","52197749969099207343387467969348653784"]}},{"deprecated":false,"digest":{"line_hashes":["221389370459541310429415030876937229908","254575959544664122688762453977417508098","161138589539862284574362943797446021856","76820706862145459399099202330568708086"],"threshold":0.9},"id":"CVE-2026-61899-dd67cc76","signature_type":"Line","signature_version":"v1","source":"https://github.com/apache/tapestry-5/commit/6b58f74daa8668e590f645b2b83c866da273e009","target":{"file":"tapestry-core/src/test/java/org/apache/tapestry5/integration/app1/pages/Index.java"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61899.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}