CVE-2026-94251: Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource
Low-severity vulnerability in Apache Sling Security Bundle where ContentDispositionFilter misses certain resource address shapes, fixed in v1.3.12.
A low-severity vulnerability, CVE-2026-94251, has been reported in the Apache Sling Security Bundle. The ContentDispositionFilter incorrectly mediates only one address/API shape of a resource, potentially leaving it unprotected. Users should upgrade to version 1.3.12 to fix the issue.
- Low-severity vulnerability in Apache Sling Security Bundle.
- ContentDispositionFilter fails to mediate all resource address shapes.
- Patched in version 1.3.12.
Vulnerabilities mentionedAll →
- CVE-2026-942516.5—Content-Disposition filter bypass in Apache Sling Security Bundle before 1.3.12published · Apache Software Foundation Apache Sling Security Bundle (ContentDispositionFilter)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-94251 | Content-Disposition filter bypass in Apache Sling Security Bundle before 1.3.12 The ContentDispositionFilter in the Apache Sling Security Bundle only mediates one address/API shape for accessing a repository resource, so the same content can be fetched through alternative URL or servlet forms that the filter never inspects. This is a protection-mechanism failure: content that should have been forced into an 'attachment' download (for example user-stored HTML or SVG that could be rendered inline) can instead be served inline in the site's origin. An unauthenticated remote attacker who can get such content into the repository could then trick a victim's browser into executing it in-context, yielding content-type confusion / stored cross-site scripting with low confidentiality and low integrity impact (CVSS 3.1: 6.5). All deployments running the Sling Security Bundle before 1.3.12 are affected — note that Sling is also the underlying web framework inside Adobe Experience Manager (AEM), so enterprise AEM stacks may embed an affected bundle version. No public proof of concept is known, the flaw is not in CISA's KEV catalog, and there are no reports of exploitation in the wild. |
Posted by Joerg Hoh on Sep 23 Severity: low Affected versions: - Apache Sling Security Bundle before 1.3.12 Description: A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource This issue affects Apache Sling Security Bundle: before 1.3.12. Users are recommended to upgrade to version 1.3.12, which fixes the issue. This issue is being tracked as SLING-13316 Credit: The Apache Software Foundation...
This source does not provide full text. Read it at seclists.org.