PT-2026-72884 · Apache · Apache Struts

·

CVE-2026-73634

·

Published

2026-08-15

·

Updated

2026-08-15

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Struts versions 6.0.0 through 6.10.0 Apache Struts versions 7.0.0 through 7.2.1
Description An uncontrolled resource consumption issue exists where an application exposing an endpoint for collecting Content Security Policy (CSP) violation reports reads the submitted report into memory without limits. This allows a single request to exhaust the heap, leading to a denial of service for other users. These endpoints are typically accessible without authentication. The core distribution does not map such an endpoint by default, meaning applications that do not collect violation reports are not affected.
Recommendations Upgrade Apache Struts versions 6.0.0 through 6.10.0 to version 6.11.0. Upgrade Apache Struts versions 7.0.0 through 7.2.1 to version 7.3.0.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73634

Affected Products

Apache Struts