PT-2026-72027 · Apache · Apache Struts
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Struts versions 2.1.8 through 2.3.37
Apache Struts versions 2.5.0 through 2.5.33
Apache Struts versions 6.0.0 through 6.10.0
Apache Struts versions 7.0.0 through 7.2.1
Description
An uncontrolled resource consumption issue exists in the JSON plugin. When an application is configured to populate actions from a JSON request body, the plugin reads the body into memory without a bound on the accepted size. This can allow a single request to exhaust the heap, resulting in a denial of service for other users. The configurable JSON input length limit does not prevent this behavior. This issue only affects applications that use the optional JSON plugin with JSON request-body handling enabled.
Recommendations
Upgrade versions 2.1.8 through 6.10.0 to version 6.11.0.
Upgrade versions 7.0.0 through 7.2.1 to version 7.3.0.
As a temporary mitigation, disable the JSON plugin or disable JSON request-body handling.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Struts