CVE-2026-104714
- EPSS 0.49%
- Veröffentlicht 05.10.2026 18:36:49
- Zuletzt bearbeitet 06.10.2026 15:17:12
Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts. Where a localized message formats a date or time argument, the formatter retained for that message by the application-wide tex...
CVE-2026-104713
- EPSS 0.42%
- Veröffentlicht 05.10.2026 18:36:09
- Zuletzt bearbeitet 06.10.2026 15:17:12
Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin. A request body is read into memory without any bound on how much will be accepted, so a single request can cause the server to allocate memory in pro...
CVE-2026-104712
- EPSS 0.58%
- Veröffentlicht 05.10.2026 18:35:41
- Zuletzt bearbeitet 06.10.2026 15:17:12
Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework ca...
CVE-2026-104711
- EPSS 0.86%
- Veröffentlicht 05.10.2026 18:35:10
- Zuletzt bearbeitet 06.10.2026 15:17:12
Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inj...
CVE-2026-73632
- EPSS 0.38%
- Veröffentlicht 15.08.2026 10:38:53
- Zuletzt bearbeitet 18.08.2026 17:47:08
Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become observable in an...
CVE-2026-73631
- EPSS 0.38%
- Veröffentlicht 15.08.2026 10:38:28
- Zuletzt bearbeitet 18.08.2026 17:47:40
Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one request to become observable in another, and configur...
CVE-2026-73635
- EPSS 0.7%
- Veröffentlicht 15.08.2026 10:38:08
- Zuletzt bearbeitet 18.08.2026 17:45:16
Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause...
CVE-2026-73634
- EPSS 0.73%
- Veröffentlicht 15.08.2026 10:37:37
- Zuletzt bearbeitet 18.08.2026 17:46:04
Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, so a singl...
CVE-2026-73633
- EPSS 0.5%
- Veröffentlicht 14.08.2026 14:16:51
- Zuletzt bearbeitet 18.08.2026 13:15:41
Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, so a...
CVE-2025-68493
- EPSS 37.06%
- Veröffentlicht 11.01.2026 13:05:36
- Zuletzt bearbeitet 15.07.2026 02:17:50
Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.