Apache Struts: Unbounded growth of localized-text caches driven by the request locale
Summary
| CVE | CVE-2026-73635 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 11:16:27 UTC |
| Updated | 2026-08-15 11:16:27 UTC |
| Description | Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause the framework's internal localized-text caches to grow without bound and exhaust the Java heap, denying service to other users. Applications that configure a fixed locale are not affected. This issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1. Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue. |
Risk And Classification
Problem Types: CWE-770 | CWE-770 CWE-770 Allocation of Resources Without Limits or Throttling
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Struts | affected 2.0.0 2.3.37 semver | Not specified |
| CNA | Apache Software Foundation | Apache Struts | affected 2.5.0 2.5.33 semver | Not specified |
| CNA | Apache Software Foundation | Apache Struts | affected 6.0.0 6.10.0 semver | Not specified |
| CNA | Apache Software Foundation | Apache Struts | affected 7.0.0 7.2.1 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cwiki.apache.org/confluence/display/WW/S2-074 | [email protected] | cwiki.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Kuniyoshi Noguchi (野口 晋義), (@KuniNogu) (en)
There are currently no legacy QID mappings associated with this CVE.