PT-2026-72884 · Apache · Apache Struts
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Struts versions 6.0.0 through 6.10.0
Apache Struts versions 7.0.0 through 7.2.1
Description
An uncontrolled resource consumption issue exists where an application exposing an endpoint for collecting Content Security Policy (CSP) violation reports reads the submitted report into memory without limits. This allows a single request to exhaust the heap, leading to a denial of service for other users. These endpoints are typically accessible without authentication. The core distribution does not map such an endpoint by default, meaning applications that do not collect violation reports are not affected.
Recommendations
Upgrade Apache Struts versions 6.0.0 through 6.10.0 to version 6.11.0.
Upgrade Apache Struts versions 7.0.0 through 7.2.1 to version 7.3.0.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Struts