Junglewise Threat Intelligence

CVE-2026-42509: Apache Wicket Cross-site Scripting in web page generation

CVE-2026-42509 · Severity: medium · CVSS 6.1 · Published 2026-05-06

Technologies: Apache Software Foundation Wicket. Vendors: Apache, Apache Software Foundation.

Executive brief

Apache Wicket, a popular Java framework for building web applications, is vulnerable to a security flaw that could allow attackers to run malicious scripts in a user's browser. This type of attack, known as Cross-Site Scripting (XSS), can be used to steal sensitive information like session cookies or perform actions on behalf of the user without their consent. Organizations using affected versions should update to the latest patched version to protect their users and data.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Apache Wicket due to improper neutralization of user-controllable input during web page generation (CWE-79). Specifically, crafted strings can break out of JavaScript sequences within the framework's output. The vulnerability is exploitable via the network without authentication, though it requires user interaction (UI:R) and results in a scope change (S:C). Attackers can leverage this to execute arbitrary JavaScript in the context of the victim's browser session. The issue is fixed in version 10.9.0.

Affected products

  • Apache Wicket 8.0.0 through 8.17.0, 9.0.0 through 9.22.0, 10.0.0 through 10.8.0

Timeline

  • 2026-05-06: disclosed
  • 2026-05-06: advisory
  • 2026-05-11: patched: GitHub advisory reviewed and patch version confirmed.

References

Related threats