CyberRota Analysis
AI-GeneratedApache Tapestry versions 5.5.0 and above are vulnerable to an issue that allows attackers to download classpath assets through specially crafted URLs, potentially exposing sensitive application data. Organizations using affected versions should prioritize upgrading to version 5.9.1 to mitigate this risk and protect their applications from unauthorized access.
CVE
CVE-2026-61899
Severity
HIGH
CVSS
7.5
EPSS
0.41%
Apache
Original NVD Description
Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Users are recommended to upgrade to version 5.9.1, which fixes this issue.