oss-sec mailing list archives

CVE-2026-73192: Apache Sling XSS: XSS possible through XSSAPI.getValidHref()


From: Joerg Hoh <joerghoh () apache org>
Date: Wed, 23 Sep 2026 08:25:54 +0000

Severity: low 

Affected versions:

- Apache Sling XSS before 2.4.12

Description:

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when 
using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may allow an attacker to perform a 
reflected cross-site scripting (XSS) attack in every feature using this method. In order to successfully attack an 
application, the attacker needs to be able to submit a value which is not correctly sanitized by that library.

Upgrade to Apache Sling XSS >= 2.4.12

Credit:

Apache Sling would like to thank github user Vectrain51 and n0mi1k for reporting this issue (finder)

References:

https://sling.apache.org/news.html
https://sling.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-73192


Current thread: