🔐 CVE Alert

CVE-2026-94251

MEDIUM 6.5

Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource

CVSS Score
6.5
EPSS Score
0.2%
EPSS Percentile
9th

A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource This issue affects Apache Sling Security Bundle: before 1.3.12. Users are recommended to upgrade to version 1.3.12, which fixes the issue.

CWE CWE-693
Vendor apache software foundation
Product apache sling security bundle
Published Sep 23, 2026
Last Updated Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache sling security bundle

Be the first to know when new medium vulnerabilities affecting apache software foundation apache sling security bundle are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache Sling Security Bundle
0 < 1.3.12

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread/7zo0drh75qmk1xn7940hy4pxjs6h2b10

Credits

The Apache Software Foundation Claude Code