Improper Entity Reference Handling in Apache Sling by Apache
CVE-2026-92001

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-92001?

A significant security vulnerability exists in Apache Sling that involves improper restriction of recursive entity references in Document Type Definitions (DTD). This flaw allows for XML entity expansion, potentially leading to Denial of Service (DoS) through resource exhaustion. Versions prior to 2.4.12 are impacted. Users are strongly advised to upgrade to the latest version to mitigate this risk and enhance their security posture.

Affected Version(s)

Apache Sling XSS 0 < 2.4.12

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Apache Software Foundation
Claude Code
.