A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to upgrade to version 1.3.2, which fixes the issue.
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Sling Security Bundle | 0 ~ 1.3.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-31377 | 7.5 HIGH | Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service |
| CVE-2026-76183 | Apache Tomcat: Bypass of security constraints for WebSocket endpoints | |
| CVE-2026-82331 | Apache BuildStream: tar source extraction escape | |
| CVE-2026-73192 | Apache Sling XSS: XSS possible through XSSAPI.getValidHref() | |
| CVE-2026-92001 | Apache Sling XSS: Missing parser resource limits | |
| CVE-2026-91999 | Apache Sling XSS: Improper escaping in the XSS Webconsole plugin | |
| CVE-2026-91852 | Apache Sling XSS: CWE-79 multiple raw-string break-outs and ReDOS in XSSImpl | |
| CVE-2026-96443 | Apache Doris: JDBC driver URL validation bypass leads to remote code execution | |
| CVE-2026-91928 | Apache Sling XSS: Sanitizer bypass, uncontrolled resource consumption and failure pf prote | |
| CVE-2026-94251 | Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape | |
| CVE-2026-73581 | Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate us | |
| CVE-2026-75973 | Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured | |
| CVE-2026-86247 | Apache Tomcat Native: Client certificate requirements can be down-graded | |
| CVE-2026-77756 | Apache Tomcat: Transfer-Encoding honored for HTTP/1.0 requests | |
| CVE-2026-77762 | Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request | |
| CVE-2026-77791 | Apache Tomcat: DoS via busy wait during WebSocket close | |
| CVE-2026-78383 | Apache Tomcat: AJP DoS via missing request body | |
| CVE-2026-78437 | Apache Tomcat: HTTP/2 DoS via malformed request | |
| CVE-2026-79677 | Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout | |
| CVE-2026-86248 | Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with |
Showing top 20 of 25 CVEs. View all on vendor page → →
No comments yet