Protection mechanism failure in Apache Wicket - CVE-2026-66391
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass content security policy protections.
The vulnerability exists due to protection mechanism failure and use of insufficiently random values in csp header handling when processing web requests. A remote attacker can trigger responses with leaked or missing csp headers to bypass content security policy protections.