JVN#08517956
Apache Struts 2 vulnerable to resource exhaustion
Overview
Apache Struts 2 provided by The Apache Software Foundation contains a resource exhaustion vulnerability.
Products Affected
- Apache Struts 2 versions 6.0.0 through 6.10.0
- Apache Struts 2 versions 7.0.0 through 7.2.1
Description
Apache Struts 2 provided by The Apache Software Foundation contains the following vulnerability:
- Allocation of resources without limits or throttling (CWE-770)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Base Score 8.7
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Base Score 7.5
- CVE-2026-73635
Impact
Heap memory may be exhausted, causing the affected device to enter a denial-of-service (DoS) state.
Solution
Update the software
The vulnerability has been fixed in the versions 7.3.0 and 6.11.0.
Update the software to the latest version according to the information provided by the developer.
While the vulnerability exists in the following versions, it will not be fixed as they are EOL.
- Versions 2.0.0 through 2.3.37
- Versions 2.5.0 through 2.5.33
Applications that configure a fixed locale via the
struts.locale constant are not affected.
Vendor Status
| Vendor | Link |
| The Apache Software Foundation | S2-074 |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
KuniyoshiNoguchi reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
|
| JVN iPedia |
JVNDB-2026-000121 |