CVE-2026-94251 PUBLISHED

Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource

Assigner: apache
Reserved: 21.09.2026 Published: 23.09.2026 Updated: 23.09.2026

A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource

This issue affects Apache Sling Security Bundle: before 1.3.12.

Users are recommended to upgrade to version 1.3.12, which fixes the issue.

Product Status

Vendor Apache Software Foundation
Product Apache Sling Security Bundle
Versions Default: unaffected
  • affected from 0 to 1.3.12 (excl.)

Credits

  • The Apache Software Foundation finder
  • Claude Code tool

References

Problem Types

  • CWE-693 CWE