CVE-2026-92001: Apache Sling XSS: Missing parser resource limits
Apache Sling XSS before 2.4.12 has an XML entity expansion vulnerability (CVE-2026-92001).
Apache Sling XSS before version 2.4.12 contains a vulnerability (CVE-2026-92001) allowing improper restriction of recursive entity references in DTDs, also known as XML entity expansion. The flaw is tracked as SLING-13336 and was discovered by the Apache Software Foundation. The vendor has released a patch in version 2.4.12 to address the issue.