- Description
- Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, so a single request can exhaust the heap and deny service to other users. Such endpoints are ordinarily reachable without authentication. The core distribution maps no such endpoint by default; applications that do not collect violation reports are not affected. This issue affects Apache Struts: from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1. Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.
- Source
- security@apache.org
- NVD status
- Analyzed
- Products
- struts
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- security@apache.org
- CWE-400
- Hype score
- Not currently trending
🚨 Apache Struts has patched multiple security issues, including three DoS vulnerabilities tracked as CVE-2026-73633, CVE-2026-73634, and CVE-2026-73635. Two additional flaws affect the JSON plugin, highlighting the risk for applications running affected Struts components.
@ThreatWire_
16 Aug 2026
1708 Impressions
2 Retweets
9 Likes
3 Bookmarks
0 Replies
0 Quotes
Apache Struts DoS flaws span CVE-2026-73633, CVE-2026-73634, and CVE-2026-73635, plus two JSON plugin bugs. Upgrade to 7.3.0. #ApacheStruts #Struts2 #DoS #CVE #JavaWeb #CyberSecurity #InfoSec #Vulnerability https://t.co/Rq2S4ojv18
@Daily_CyberSec
15 Aug 2026
470 Impressions
1 Retweet
4 Likes
0 Bookmarks
0 Replies
0 Quotes
Apache Strutsの脆弱性(Moderate: CVE-2026-73631, CVE-2026-73633, CVE-2026-73634, CVE-2026-73635, Low: CVE-2026-73632) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #apache #struts #dos https://t.co/8XUCJQetCY
@omokazuki
14 Aug 2026
125 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
Apache Strutsで5件の脆弱性(S2-070~S2-074) CVE-2026-73631 CVE-2026-73632 CVE-2026-73633 CVE-2026-73634 CVE-2026-73635 https://t.co/M7OFPs9BmA
@autumn_good_35
14 Aug 2026
617 Impressions
2 Retweets
3 Likes
1 Bookmark
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3BC456E1-1D13-404B-A50F-A9DA579309F1",
"versionEndExcluding": "6.11.0",
"versionStartIncluding": "6.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*",
"matchCriteriaId": "54C39F3E-9829-4AB5-80DD-920D4F86ED0E",
"versionEndExcluding": "7.3.0",
"versionStartIncluding": "7.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]