CVE-2024-53299: Apache Wicket

Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.

The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources. Users are recommended to upgrade to versions 9.19.0 or 10.3.0, which fixes this issue.

Affected products

  • Apache Wicket: from 7.0.0, up to and including 7.18.0; from 8.0.0, up to and including 8.16.0; from 9.0.0, before 9.19.0 (fixed in 9.19.0); from 10.0.0, before 10.3.0 (fixed in 10.3.0)

Published 2025-01-23. Last modified 2026-06-17.