Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN795
_____________________________________________________________________

DATE                : 29/07/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Apache Wicket versions prior to
                                       10.10.0.
 
=====================================================================
https://lists.apache.org/thread/o0tv8kygzo06o2pj90ppz43hhgson194
https://lists.apache.org/thread/7py2fc86jw90220ph2tmf4gtxtl6ton2
_____________________________________________________________________

CVE-2026-66390: Apache Wicket: crafted Link URL strings can break out
of the JavaScript sequence

Severity: important 

Affected versions:

- Apache Wicket 9.0.0 through 9.23.0
- Apache Wicket 10.0.0 through 10.9.0

Description:

Improper Neutralization of Input During Web Page Generation
('Cross-site Scripting') vulnerability in Apache Wicket.

This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from
10.0.0 through 10.9.0.

Users are recommended to upgrade to version 10.10.0, which fixes
the issue.

References:

https://wicket.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-66390

_____________________________________________________________________

CVE-2026-66391: Apache Wicket: leaked and missing CSP headers
Severity: important 

Affected versions:

- Apache Wicket 9.0.0 through 9.23.0
- Apache Wicket 10.0.0 through 10.9.0

Description:

Use of Insufficiently Random Values, Protection Mechanism Failure
vulnerability in Apache Wicket.

This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from
10.0.0 through 10.9.0.

Users are recommended to upgrade to version 10.10.0, which fixes
the issue.

References:

https://wicket.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-66391


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




