Severity: moderate

Affected versions:
- Apache Struts (org.apache.struts:struts2-core) 6.0.0 through 6.10.0
- Apache Struts (org.apache.struts:struts2-core) 7.0.0 through 7.2.1

Description:
Uncontrolled resource consumption vulnerability in Apache Struts. An
application that exposes an endpoint collecting Content Security
Policy violation reports reads the submitted report into memory
without bounding how much it will accept, so a single request can
exhaust the heap and deny service to other users. Such endpoints are
ordinarily reachable without authentication. The core distribution
maps no such endpoint by default; applications that do not collect
violation reports are not affected.

This issue affects Apache Struts: from 6.0.0 through 6.10.0, from
7.0.0 through 7.2.1.

Users are recommended to upgrade to version 6.11.0 or 7.3.0, which
fixes the issue.

Credit:
Michael Mullins (finder)

References:
https://cwiki.apache.org/confluence/display/WW/S2-073
https://www.cve.org/CVERecord?id=CVE-2026-73634


On behalf of the Apache Struts project
Ɓukasz Lenart

Reply via email to