CVE-2026-73631Disclosure(apache / struts)

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one request to become observable in another, and configured parsing limits not to be enforced as intended. Populating actions from a JSON request body is not enabled by default; applications that do not use the JSON plugin are not affected. This issue affects Apache Struts: 7.2.1. Users are recommended to upgrade to version 7.3.0, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-567

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • struts

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
struts

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-14: 2Technical Details · 2026-08-14: 108-14
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Autumn Good@autumn_good_35
    General

    Apache Strutsで5件の脆弱性(S2-070~S2-074) CVE-2026-73631 CVE-2026-73632 CVE-2026-73633 CVE-2026-73634 CVE-2026-73635 https://struts.apache.org/announce-2026

    Post summary

    The tweet announces five new Apache Struts vulnerabilities (CVE-2026-73631 to CVE-2026-73635) and provides a link to the Struts announcement page.

    02031726
    7.1K followersView on X
  • Kazuki Omo@omokazuki
    Disclosure

    Apache Strutsの脆弱性(Moderate: CVE-2026-73631, CVE-2026-73633, CVE-2026-73634, CVE-2026-73635, Low: CVE-2026-73632) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #apache #struts #dos https://security.sios.jp/vulnerability/struts-security-vulnerability-20260814/

    Post summary

    The post announces several moderate and low severity Apache Struts CVEs and points to a vulnerability disclosure page for details.

    00001145
    372 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachestruts7.2.1--

Explore more