GHSA-8vvp-525h-cxf9 · Severity: medium · Ecosystem: maven — Cross-Site Request Forgery in Apache Wicket
An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series. Apache Wicket 8.x does not support CSRF protection via the fetch metadata headers and as such is not affected. Users are recommended to upgrade to version 9.17.0 or 10.0.0, which fixes the issue.
Conclusion & alert: CVE-2024-27439 is rated Moderate Risk (42.7/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.68%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.57% | 0.68% | +0.11% |
| 2 | 2026-04-07 | 0.43% | 0.57% | +0.13% |
| 3 | 2025-12-31 | — | 0.43% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
3.9 | 2.5 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-8vvp-525h-cxf9 · Severity: medium · Ecosystem: maven — Cross-Site Request Forgery in Apache Wicket
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2024-27439 |
| URL | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2024/03/19/2 | Mailing List |
| https://lists.apache.org/thread/o825rvjjtmz3qv21ps5k7m2w9193g1lo | Mailing List Vendor Advisory |