oss-sec mailing list archives

CVE-2026-61372: Apache Jena Fuseki: Web requests using SPARQL Update can escape file restrictions


From: Andy Seaborne <andy () apache org>
Date: Mon, 03 Aug 2026 15:11:44 +0000

Severity: important 

Affected versions:

- Apache Jena Fuseki through 6.1.0

Description:

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki.

This issue affects Apache Jena Fuseki: through 6.1.0.

Users are recommended to upgrade to version 6.2.0, which fixes the issue.

References:

https://jena.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-61372


Current thread: