Uncontrolled Resource Consumption Vulnerability in Apache Struts JSON Plugin
CVE-2026-73633
7.5HIGH
What is CVE-2026-73633?
The JSON plugin in Apache Struts exhibits an uncontrolled resource consumption vulnerability, allowing attackers to send a single request that can consume excessive memory resources. This can lead to denial of service for other users, as the plugin reads JSON request bodies into memory without imposing limits. While the plugin is optional, applications utilizing it for JSON request handling are susceptible. It is essential for users to upgrade to versions 6.11.0 or 7.3.0 to mitigate this issue effectively.
Affected Version(s)
Apache Struts 2.1.8 <= 2.3.37
Apache Struts 2.5.0 <= 2.5.33
Apache Struts 6.0.0 <= 6.10.0