CVE-2026-73192: Apache Sling Xss Protection API
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack in every feature using this method. In order to successfully attack an application, the attacker needs to be able to submit a value which is not correctly sanitized by that library. Upgrade to Apache Sling XSS >= 2.4.12
Affected products
- Apache Sling Xss Protection API: before 2.4.12 (fixed in 2.4.12)
Published 2026-09-23. Last modified 2026-09-30.