Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN809
_____________________________________________________________________

DATE                : 04/08/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Apache Jena Fuseki versions
                                  prior to 6.2.0.
 
=====================================================================
https://lists.apache.org/thread/vrtjgy25kvxvy1tmbxjswy7sqh0km8qj
_____________________________________________________________________

CVE-2026-61372: Apache Jena Fuseki: Web requests using SPARQL Update
can escape file restrictions

Severity: important 

Affected versions:

- Apache Jena Fuseki through 6.1.0

Description:

Improper Limitation of a Pathname to a Restricted Directory
('Path Traversal') vulnerability in Apache Jena Fuseki.

This issue affects Apache Jena Fuseki: through 6.1.0.

Users are recommended to upgrade to version 6.2.0, which
fixes the issue.

References:

https://jena.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-61372

=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




