CVE-2026-73192: Apache Sling XSS: XSS possible through XSSAPI.getValidHref()
Low-severity reflected XSS vulnerability disclosed in Apache Sling XSS library's getValidHref() method, patched in v2.4.12.
A low-severity reflected cross-site scripting (XSS) vulnerability, CVE-2026-73192, has been disclosed in the Apache Sling XSS library. The flaw exists in the XSSAPI.getValidHref() method, potentially allowing script injection. Users are advised to upgrade to version 2.4.12 to mitigate the risk.