Junglewise Threat Intelligence

CVE-2026-73192: Apache Sling XSS reflected XSS in getValidHref()

CVE-2026-73192 · Severity: medium · CVSS 6.1 · Published 2026-09-23

Technologies: Apache Sling XSS. Vendors: Apache.

Executive brief

Apache Sling XSS is a library that sanitizes user input to prevent cross-site scripting attacks in web applications. A flaw in the getValidHref() method fails to properly neutralize malicious input, allowing an attacker to inject and execute arbitrary JavaScript code in a user's browser when the library is used in an application. An attacker needs to submit an unsanitized value through an application that uses this vulnerable method to exploit the flaw.

Technical details

The vulnerability is an improper input neutralization (CWE-79) in the XSSAPI.getValidHref() method that permits reflected XSS attacks. The flaw requires attacker-controlled input to be passed to the vulnerable method without additional sanitization by the consuming application. The issue is resolved in Apache Sling XSS version 2.4.12 and later.

Affected products

  • Apache Sling XSS 2.4.10 and prior

Timeline

  • 2026-09-23: disclosed

References

Related threats