Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319

Apache Sling Security Bundle: origin validation error

High7.3CVE-2026-94243 · Published Sep 23, 2026 · updated Oct 6, 2026

A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to upgrade to version 1.3.2, which fixes the issue.

Affected versions

PackageAffectedFixed in
Apache Sling Security Bundle
Product
< 1.3.21.3.2
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache Tomcat Native: insecure default
Critical9.1Sep 23
Apache Tomcat Native: race condition
High7.4Sep 23
Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake...
High7.5Sep 23
Improper Check for Certificate Revocation vulnerability in Apache Tomcat
Medium6.5Sep 23
Apache Tomcat: authentication bypass
Critical9.8Sep 23
Apache Tomcat: race condition
High8.1Sep 23