Cross-site Scripting Vulnerability in Apache Sling XSS by Apache
CVE-2026-73192

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-73192?

This vulnerability arises due to improper handling of user input during web page generation, allowing an attacker to execute a reflected Cross-site Scripting (XSS) attack through the XSSAPI.getValidHref() method. If the attacker submits a value that is inadequately sanitized, they can manipulate the application and potentially compromise security across various functionalities. The issue is present in Apache Sling XSS version 2.4.10 and earlier. Users are advised to upgrade to version 2.4.12 or later to mitigate the risk.

Affected Version(s)

Apache Sling XSS 0 < 2.4.12

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Apache Sling would like to thank github user Vectrain51 and n0mi1k for reporting this issue
.