oss-sec mailing list archives
CVE-2026-73192: Apache Sling XSS: XSS possible through XSSAPI.getValidHref()
From: Joerg Hoh <joerghoh () apache org>
Date: Wed, 23 Sep 2026 08:25:54 +0000
Severity: low
Affected versions:
- Apache Sling XSS before 2.4.12
Description:
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when
using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may allow an attacker to perform a
reflected cross-site scripting (XSS) attack in every feature using this method. In order to successfully attack an
application, the attacker needs to be able to submit a value which is not correctly sanitized by that library.
Upgrade to Apache Sling XSS >= 2.4.12
Credit:
Apache Sling would like to thank github user Vectrain51 and n0mi1k for reporting this issue (finder)
References:
https://sling.apache.org/news.html
https://sling.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-73192
Current thread:
- CVE-2026-73192: Apache Sling XSS: XSS possible through XSSAPI.getValidHref() Joerg Hoh (Sep 23)
