CVE-2026-73632
- EPSS 0.38%
- Veröffentlicht 15.08.2026 10:38:53
- Zuletzt bearbeitet 18.08.2026 17:47:08
Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become observable in an...
CVE-2026-73631
- EPSS 0.38%
- Veröffentlicht 15.08.2026 10:38:28
- Zuletzt bearbeitet 18.08.2026 17:47:40
Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one request to become observable in another, and configur...
CVE-2026-73635
- EPSS 0.7%
- Veröffentlicht 15.08.2026 10:38:08
- Zuletzt bearbeitet 18.08.2026 17:45:16
Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause...
CVE-2026-73634
- EPSS 0.73%
- Veröffentlicht 15.08.2026 10:37:37
- Zuletzt bearbeitet 18.08.2026 17:46:04
Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, so a singl...
CVE-2026-73633
- EPSS 0.5%
- Veröffentlicht 14.08.2026 14:16:51
- Zuletzt bearbeitet 18.08.2026 13:15:41
Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, so a...
CVE-2025-68493
- EPSS 37.06%
- Veröffentlicht 11.01.2026 13:05:36
- Zuletzt bearbeitet 15.07.2026 02:17:50
Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.
CVE-2025-66675
- EPSS 0.59%
- Veröffentlicht 10.12.2025 09:32:58
- Zuletzt bearbeitet 16.12.2025 18:39:51
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6....
CVE-2025-64775
- EPSS 1.49%
- Veröffentlicht 01.12.2025 16:07:36
- Zuletzt bearbeitet 26.01.2026 11:30:04
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6....
CVE-2024-53677
- EPSS 78.2%
- Veröffentlicht 11.12.2024 16:15:14
- Zuletzt bearbeitet 15.07.2025 16:30:19
File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. This i...
CVE-2023-50164
- EPSS 80.82%
- Veröffentlicht 07.12.2023 09:15:07
- Zuletzt bearbeitet 13.02.2025 18:15:49
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2...