Severity: moderate 

Affected versions:

- Apache Sling XSS before 2.4.12

Description:

Improper restriction of recursive entity references in DTDs ('XML entity 
expansion') vulnerability in Apache Sling XSS.



This issue affects Apache Sling XSS: before 2.4.12.



Users are recommended to upgrade to version 2.4.12, which fixes the issue.

This issue is being tracked as SLING-13336 

Credit:

The Apache Software Foundation (finder)
Claude Code (tool)

References:

https://sling.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-92001
https://issues.apache.org/jira/browse/SLING-13336

Reply via email to