๐Ÿ” CVE Alert

CVE-2026-73192

MEDIUM 6.1

Apache Sling XSS: XSS possible through XSSAPI.getValidHref()

CVSS Score
6.1
EPSS Score
0.2%
EPSS Percentile
11th

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack in every feature using this method. In order to successfully attack an application, the attacker needs to be able to submit a value which is not correctly sanitized by that library. Upgrade to Apache Sling XSS >= 2.4.12

CWE CWE-79
Vendor apache software foundation
Product apache sling xss
Published Sep 23, 2026
Last Updated Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache sling xss

Be the first to know when new medium vulnerabilities affecting apache software foundation apache sling xss are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Sling XSS
0 < 2.4.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
sling.apache.org: https://sling.apache.org/news.html

Credits

Apache Sling would like to thank github user Vectrain51 and n0mi1k for reporting this issue