Known Vulnerabilities for Apache Struts by Apache Software Foundation
Listed below are 6 of the newest known vulnerabilities associated with "Apache Struts" by "Apache Software Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73635 json | Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the ... | Not Provided | 2026-08-15 | 2026-08-17 |
| CVE-2026-73634 json | Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content ... | Not Provided | 2026-08-15 | 2026-08-17 |
| CVE-2026-73633 json | Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to pop... | Not Provided | 2026-08-14 | 2026-08-14 |
| CVE-2026-73632 json | Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state... | Not Provided | 2026-08-15 | 2026-08-17 |
| CVE-2026-73631 json | Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could ... | Not Provided | 2026-08-15 | 2026-08-17 |
| CVE-2025-68493 json | Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.... | Not Provided | 2026-01-11 | 2026-07-15 |