PT-2026-72027 · Apache · Apache Struts

·

CVE-2026-73633

·

Published

2026-08-14

·

Updated

2026-08-14

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Struts versions 2.1.8 through 2.3.37 Apache Struts versions 2.5.0 through 2.5.33 Apache Struts versions 6.0.0 through 6.10.0 Apache Struts versions 7.0.0 through 7.2.1
Description An uncontrolled resource consumption issue exists in the JSON plugin. When an application is configured to populate actions from a JSON request body, the plugin reads the body into memory without a bound on the accepted size. This can allow a single request to exhaust the heap, resulting in a denial of service for other users. The configurable JSON input length limit does not prevent this behavior. This issue only affects applications that use the optional JSON plugin with JSON request-body handling enabled.
Recommendations Upgrade versions 2.1.8 through 6.10.0 to version 6.11.0. Upgrade versions 7.0.0 through 7.2.1 to version 7.3.0. As a temporary mitigation, disable the JSON plugin or disable JSON request-body handling.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73633

Affected Products

Apache Struts