PT-2026-72883 · Apache · Apache Struts

·

CVE-2026-73632

·

Published

2026-08-15

·

Updated

2026-08-15

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Struts version 7.2.1
Description A data exposure issue exists in the JSON plugin where per-response serialization state may be shared across concurrent requests. This allows response content from one request to be observed by another. The issue specifically affects the SMD / JSON-RPC handling of the JSON interceptor, which is disabled by default. Applications utilizing the json result type are not impacted.
Recommendations Upgrade to version 7.3.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73632

Affected Products

Apache Struts