CVE-2026-92001: Apache Sling XSS: Missing parser resource limits
Apache Sling XSS before 2.4.12 has an XML entity expansion vulnerability (CVE-2026-92001).
Apache Sling XSS before version 2.4.12 contains a vulnerability (CVE-2026-92001) allowing improper restriction of recursive entity references in DTDs, also known as XML entity expansion. The flaw is tracked as SLING-13336 and was discovered by the Apache Software Foundation. The vendor has released a patch in version 2.4.12 to address the issue.
- Apache Sling XSS before 2.4.12 has an XML entity expansion vulnerability.
- The flaw is tracked as SLING-13336 and is rated moderate.
- Users are advised to upgrade to version 2.4.12 to fix the issue.
Vulnerabilities mentionedAll →
- CVE-2026-920016.1—XML Entity Expansion Flaw in Apache Sling XSS Library Before 2.4.12published · Apache Software Foundation Apache Sling XSS
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-92001 | XML Entity Expansion Flaw in Apache Sling XSS Library Before 2.4.12 Apache Sling XSS, the bundle that sanitizes and filters markup in Apache Sling-based web applications, improperly restricts recursive entity references in DTDs (CWE-776) in all versions before 2.4.12. An attacker can submit content containing deeply nested XML entity references, which the XSS filter's parser expands without adequate resource limits; the related advisory headline also points to missing parser resource limits. Because the vector is scored AV:N/PR:N/UI:R with changed scope and low confidentiality and integrity impact, the practical result is a client-side attack (XSS-like behavior in a victim's browser) when a victim interacts with a page that renders the filtered content, rather than direct server compromise. Applications built on Apache Sling — including Adobe AEM-based deployments that ship the Sling XSS bundle — are affected if they run a version older than 2.4.12. No public proof of concept is known, the issue is not on CISA's KEV list, and there is no evidence of in-the-wild exploitation. |
Posted by Joerg Hoh on Sep 23 Severity: moderate Affected versions: - Apache Sling XSS before 2.4.12 Description: Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issue. This issue is being tracked as SLING-13336 Credit: The Apache Software Foundation (finder) Claude...
This source does not provide full text. Read it at seclists.org.