Published:2026/08/25  Last Updated:2026/08/25

JVN#08517956
Apache Struts 2 vulnerable to resource exhaustion

Overview

Apache Struts 2 provided by The Apache Software Foundation contains a resource exhaustion vulnerability.

Products Affected

  • Apache Struts 2 versions 6.0.0 through 6.10.0
  • Apache Struts 2 versions 7.0.0 through 7.2.1

Description

Apache Struts 2 provided by The Apache Software Foundation contains the following vulnerability:

  • Allocation of resources without limits or throttling (CWE-770)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Base Score 8.7
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Base Score 7.5
    • CVE-2026-73635

Impact

Heap memory may be exhausted, causing the affected device to enter a denial-of-service (DoS) state.

Solution

Update the software
The vulnerability has been fixed in the versions 7.3.0 and 6.11.0.
Update the software to the latest version according to the information provided by the developer.

While the vulnerability exists in the following versions, it will not be fixed as they are EOL.

  • Versions 2.0.0 through 2.3.37
  • Versions 2.5.0 through 2.5.33
Apply workaround
Applications that configure a fixed locale via the struts.locale constant are not affected.

Vendor Status

Vendor Link
The Apache Software Foundation S2-074

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

KuniyoshiNoguchi reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia JVNDB-2026-000121