Missing XML Validation vulnerability in Apache Struts, Apache Struts.
This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.
Users are recommended to upgrade to version 6.1.1, which fixes the issue.
{ "versions": [ { "introduced": "2.0.0" }, { "last_affected": "2.3.37" }, { "introduced": "6.0.0" }, { "fixed": "6.1.1" } ] }
[ { "events": [ { "introduced": "2.5.0" }, { "last_affected": "2.5.33" } ] } ]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68493.json"