{"schema_version": "1.6.1", "id": "CVE-2026-61899", "summary": "Possible classpath file download through URL manipulation", "details": "Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs.\nUsers are recommended to upgrade to version 5.9.1, which fixes this issue.", "affected": [{"ranges": [{"type": "SEMVER", "events": [{"introduced": "5.5.0"}, {"fixed": "5.9.1"}]}]}], "references": [{"type": "WEB", "url": "https://lists.apache.org/thread/6j3yojqrdsxkrfz52d0zjyrf5n9xttmw"}]}