← Vulnerability feed

Vulnerability record · CVE-2021-27850 · published 15 April 2021

CVE-2021-27850: Apache Tapestry unauthenticated RCE via asset URL blacklist bypass

Apache · Tapestry

Apache Tapestry's fix for CVE-2019-0195 used a blacklist that blocks asset URLs ending in .class, .properties or .xml, but appending a trailing slash bypasses the check and still returns the file. An attacker can retrieve AppModule.class, extract the HMAC secret used to sign serialized Java objects, and forge a signed gadget chain. The flaw is unauthenticated and network-reachable, making it a full remote code execution path.

9.8 CVSS 3.1 Critical EPSS 93% · top 0.2% CWE-200 · Information exposureCWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 10.0
93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5, 5.5.0, 5.6.2 and 5.7.0. The vulnerability I have found is a bypass of the fix for CVE-2019-0195. Recap: Before the fix of CVE-2019-0195 it was possible to download arbitrary class files from the classpath by providing a crafted asset file URL. An attacker was able to download the file `AppModule.class` by requesting the URL `http://localhost:8080/assets/something/services/AppModule.class` which contains a HMAC secret key. The fix for that bug was a blacklist filter that checks if the URL ends with `.class`, `.properties` or `.xml`. Bypass: Unfortunately, the blacklist solution can simply be bypassed by appending a `/` at the end of the URL: `http://localhost:8080/assets/something/services/AppModule.class/` The slash is stripped after the blacklist check and the file `AppModule.class` is loaded into the response. This class usually contains the HMAC secret key which is used to sign serialized Java objects. With the knowledge of that key an attacker can sign a Java gadget chain that leads to RCE (e.g. CommonsBeanUtils1 from ysoserial). Solution for this vulnerability: * For Apache Tapestry 5.4.0 to 5.6.1, upgrade to 5.6.2 or later. * For Apache Tapestry 5.7.0, upgrade to 5.7.1 or later.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with a CVSS of 9.8 and very high EPSS probability, with public exploit references available.

What it is

Apache Tapestry's fix for CVE-2019-0195 used a blacklist that blocks asset URLs ending in .class, .properties or .xml, but appending a trailing slash bypasses the check and still returns the file. An attacker can retrieve AppModule.class, extract the HMAC secret used to sign serialized Java objects, and forge a signed gadget chain. The flaw is unauthenticated and network-reachable, making it a full remote code execution path.

Impact

An attacker gains the HMAC signing key and can submit a signed malicious serialized object, achieving remote code execution with the privileges of the Tapestry application. This yields full compromise of confidentiality, integrity and availability on the affected server.

Attack surface

Reached over HTTP by requesting a crafted asset URL such as /assets/.../AppModule.class/ on a Tapestry application. No authentication and no user interaction are required; the CVSS vector is AV:N/AC:L/PR:N/UI:N.

Exploitation

Not listed in CISA KEV, but EPSS is 0.93471 (99.8th percentile) and references carry an Exploit tag, indicating public exploit material and high likelihood of attempted exploitation.

What to do

  • Upgrade Apache Tapestry: 5.4.0 through 5.6.1 to 5.6.2 or later, and 5.7.0 to 5.7.1 or later.
  • If immediate upgrade is not possible, block or reject requests whose asset paths end in .class, .properties or .xml with a trailing slash at the reverse proxy or WAF.
  • Rotate the Tapestry HMAC signing secret after patching, since exposure of the key must be assumed.
  • Restrict outbound and inbound access to the Tapestry application to trusted networks where feasible.
  • Inventory all Tapestry deployments and confirm no instance remains on an affected version.

Detection

  • Search web access logs for requests to /assets/ paths ending in .class/, .properties/ or .xml/, especially AppModule.class/.
  • Alert on HTTP 200 responses to asset URLs containing .class or .properties, which should not normally be served.
  • Monitor for deserialization errors or unexpected gadget-chain class loading in application and JVM logs.
  • Watch for anomalous outbound connections or process execution from the Tapestry application host after asset requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-27850 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-46366Apache tapestry deserialization of untrusted data vulnerabilityApache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-1…EPSS 3.4%9.8CVE-2020-17531Apache tapestry deserialization of untrusted data vulnerabilityA Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invok…EPSS 10.0%9.8CVE-2019-10071Apache tapestry observable discrepancy vulnerabilityThe code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the…EPSS 8.8%9.8CVE-2019-0195Apache tapestry deserialization of untrusted data vulnerabilityManipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker fou…EPSS 14%7.8CVE-2014-1972Apache tapestry vulnerabilityApache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attac…EPSS 9.6%7.5CVE-2026-61899Apache tapestry information exposure vulnerabilityVulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Us…EPSS 0.71%7.5CVE-2022-31781Apache tapestry inefficient regular expression (redos) vulnerabilityApache Tapestry up to version 5.8.1 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles Content Types. Specially craf…EPSS 1.9%7.5CVE-2021-30638Apache tapestry information exposure vulnerabilityInformation Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specia…EPSS 6.6%

Source: NIST National Vulnerability Database (record CVE-2021-27850), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.