CVE-2026-94243 PUBLISHED

Apache Sling Security Bundle: RefererFilter accepts weaker-than-origin evidence

Assigner: apache
Reserved: 21.09.2026 Published: 23.09.2026 Updated: 23.09.2026

A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence.

This issue affects Apache Sling Security Bundle: before 1.3.2.

Users are recommended to upgrade to version 1.3.2, which fixes the issue.

Product Status

Vendor Apache Software Foundation
Product Apache Sling Security Bundle
Versions Default: unaffected
  • affected from 0 to 1.3.2 (excl.)

Credits

  • The Apache Software Foundation finder
  • Claude Code tool

References

Problem Types

  • CWE-346 CWE