CVE-2026-94251: Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource
A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource
This issue affects Apache Sling Security Bundle: before 1.3.12.
Users are recommended to upgrade to version 1.3.12, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Sling Security Bundleto a version that resolves this vulnerability.Fixed in 1.3.12
Event History
Frequently Asked Questions
Which versions should be remediated?
Apache Sling Security Bundle versions before 1.3.12 are affected. Upgrade to version 1.3.12, which fixes the issue.
What configuration or exposure conditions make exploitation possible?
The provided information does not identify specific configuration requirements, exposed endpoints, or attacker prerequisites. It states that ContentDispositionFilter mediates only one address/API shape of a resource.
How can I determine whether my deployment is affected?
Check the deployed Apache Sling Security Bundle version. Deployments running a version earlier than 1.3.12 are affected according to the advisory.