oss-sec mailing list archives

CVE-2026-94251: Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource


From: Joerg Hoh <joerghoh () apache org>
Date: Wed, 23 Sep 2026 08:23:21 +0000

Severity: low 

Affected versions:

- Apache Sling Security Bundle before 1.3.12

Description:

A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a 
resource



This issue affects Apache Sling Security Bundle: before 1.3.12.



Users are recommended to upgrade to version 1.3.12, which fixes the issue.

This issue is being tracked as SLING-13316 

Credit:

The Apache Software Foundation (finder)
Claude Code (tool)

References:

https://sling.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-94251
https://issues.apache.org/jira/browse/SLING-13316


Current thread: