CVE-2026-94251: Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource
Low-severity vulnerability in Apache Sling Security Bundle where ContentDispositionFilter misses certain resource address shapes, fixed in v1.3.12.
A low-severity vulnerability, CVE-2026-94251, has been reported in the Apache Sling Security Bundle. The ContentDispositionFilter incorrectly mediates only one address/API shape of a resource, potentially leaving it unprotected. Users should upgrade to version 1.3.12 to fix the issue.