Apache · Apache Sling Xss · CVE-2026-92001
**Name of the Vulnerable Software and Affected Versions**
Apache Sling XSS versions prior to 2.4.12
**Description**
Improper restriction of recursive entity references in Document Type Definitions (DTDs), known as XML entity expansion, allows for potential resource exhaustion or denial of service.
**Recommendations**
Upgrade to version 2.4.12.