CVE-2026-73634Patch(apache / struts)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache struts systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, so a single request can exhaust the heap and deny service to other users. Such endpoints are ordinarily reachable without authentication. The core distribution maps no such endpoint by default; applications that do not collect violation reports are not affected. This issue affects Apache Struts: from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1. Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • struts

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-08-14); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
struts

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-14: 2Mentions · 2026-08-15: 1Mentions · 2026-08-16: 1Patch / Workaround · 2026-08-15: 1Patch / Workaround · 2026-08-16: 1Technical Details · 2026-08-15: 1Technical Details · 2026-08-16: 108-1408-1508-16
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-142
Disclosure1General1
2026-08-151
Patch1
2026-08-161
Patch1
Full discourse4 posts
  • ThreatWire@ThreatWire_
    Patch

    🚨 Apache Struts has patched multiple security issues, including three DoS vulnerabilities tracked as CVE-2026-73633, CVE-2026-73634, and CVE-2026-73635. Two additional flaws affect the JSON plugin, highlighting the risk for applications running affected Struts components. Admins should review the fixes and update to the latest supported release. #ApacheStruts #Apache #CVE #DoS #CyberSecurity #Java #Infosec

    Post summary

    The text announces that Apache Struts has patched three DoS vulnerabilities (CVE-2026-73633, CVE-2026-73634, CVE-2026-73635) affecting the JSON plugin, advising admins to review fixes and update to the latest supported release. No exploits, PoC, or active exploitation claims are mentioned.

    0201052.0K
    1.6K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Apache Struts DoS flaws span CVE-2026-73633, CVE-2026-73634, and CVE-2026-73635, plus two JSON plugin bugs. Upgrade to 7.3.0. #ApacheStruts #Struts2 #DoS #CVE #JavaWeb #CyberSecurity #InfoSec #Vulnerability https://securityonline.info/apache-struts-dos-flaws-json-plugin/

    Post summary

    Apache Struts users are advised to upgrade to version 7.3.0 to mitigate the DoS and JSON plugin bugs identified by CVE-2026-73633, 73634, and 73635; no PoC, active exploitation, or false‑positive claims are mentioned.

    01050597
    13.0K followersView on X
  • Autumn Good@autumn_good_35
    General

    Apache Strutsで5件の脆弱性(S2-070~S2-074) CVE-2026-73631 CVE-2026-73632 CVE-2026-73633 CVE-2026-73634 CVE-2026-73635 https://struts.apache.org/announce-2026

    Post summary

    The post announces five new Apache Struts vulnerabilities (S2‑070 to S2‑074) with a link to the official announcement page, but offers no further technical or remedial information.

    02031726
    7.1K followersView on X
  • Kazuki Omo@omokazuki
    Disclosure

    Apache Strutsの脆弱性(Moderate: CVE-2026-73631, CVE-2026-73633, CVE-2026-73634, CVE-2026-73635, Low: CVE-2026-73632) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #apache #struts #dos https://security.sios.jp/vulnerability/struts-security-vulnerability-20260814/

    Post summary

    The post announces a set of new Apache Struts vulnerabilities (CVE‑2026‑73631 through CVE‑2026‑73635) with severity ratings, and provides a link to a security advisory page.

    00001145
    372 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachestruts---

Explore more