CVE-2026-61899Disclosure(apache / tapestry)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache tapestry systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Users are recommended to upgrade to version 5.9.1, which fixes this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tapestry

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-08-10); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
tapestry

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-10: 1Mentions · 2026-08-11: 1Mentions · 2026-08-19: 1Patch / Workaround · 2026-08-11: 1Technical Details · 2026-08-10: 1Technical Details · 2026-08-11: 1Technical Details · 2026-08-19: 108-1008-1108-19
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-101
Disclosure1
2026-08-111
Patch1
2026-08-191
Disclosure1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-61899: Apache Tapestry: Possible classpath file download through URL manipulation https://www.openwall.com/lists/oss-security/2026/08/08/2 Severity: critical Tapestry is a component-oriented framework for creating highly scalable web applications in Java

    Post summary

    The post discloses CVE‑2026‑61899 for Apache Tapestry, describing a critical classpath file download vulnerability via URL manipulation, but no PoC, exploit code, exploitation reports, patches, or false‑positive claims are present.

    00011548
    4.7K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Apache Tapestry, Information Disclosure, #CVE-2026-61899 (Critical) -DC-Aug2026-1595 https://dailycve.com/apache-tapestry-information-disclosure-cve-2026-61899-critical-dc-aug2026-1595/

    Post summary

    The text announces a critical information disclosure vulnerability (CVE-2026-61899) affecting Apache Tapestry, pointing to a dailycve.com page for additional details.

    0000038
    229 followersView on X
  • iSECTECH@isectech_
    Patch

    Apache Tapestry 5.5.0+ has CVE-2026-61899, allowing crafted URLs to download classpath assets. Upgrade to 5.9.1 and review exposed asset routes; configuration files or packaged resources may carry more risk than the CVSS alone shows. https://lists.apache.org/thread/6j3yojqrdsxkrfz52d0zjyrf5n9xttmw

    Post summary

    CVE-2026-61899 allows attackers to download classpath assets via crafted URLs; upgrading Apache Tapestry to version 5.9.1 and reviewing exposed asset routes mitigates the vulnerability.

    0000029
    87 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetapestry---

Explore more