Uncontrolled Resource Consumption Vulnerability in Apache Struts JSON Plugin
CVE-2026-73633

7.5HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 August 2026

What is CVE-2026-73633?

The JSON plugin in Apache Struts exhibits an uncontrolled resource consumption vulnerability, allowing attackers to send a single request that can consume excessive memory resources. This can lead to denial of service for other users, as the plugin reads JSON request bodies into memory without imposing limits. While the plugin is optional, applications utilizing it for JSON request handling are susceptible. It is essential for users to upgrade to versions 6.11.0 or 7.3.0 to mitigate this issue effectively.

Affected Version(s)

Apache Struts 2.1.8 <= 2.3.37

Apache Struts 2.5.0 <= 2.5.33

Apache Struts 6.0.0 <= 6.10.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Mullins
.