CVE-2026-73631

Source
https://cve.org/CVERecord?id=CVE-2026-73631
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73631.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-73631
Published
2026-08-15T10:38:28.497Z
Modified
2026-08-20T03:55:10.877000363Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Apache Struts: Shared parsing state in the JSON plugin
Details

Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one request to become observable in another, and configured parsing limits not to be enforced as intended. Populating actions from a JSON request body is not enabled by default; applications that do not use the JSON plugin are not affected.

This issue affects Apache Struts: 7.2.1.

Users are recommended to upgrade to version 7.3.0, which fixes the issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73631.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "7.2.1"
                },
                {
                    "last_affected": "7.2.1"
                }
            ]
        }
    ],
    "cna_assigner": "apache",
    "cwe_ids": [
        "CWE-567"
    ]
}
References

Affected packages

Git / github.com/apache/struts

Affected ranges

Type
GIT
Repo
https://github.com/apache/struts
Events
Database specific
Show details
{
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:apache:struts:7.2.1:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "7.2.1"
        },
        {
            "last_affected": "7.2.1"
        }
    ]
}

Affected versions

7.*
7.2.1
Other
STRUTS_7_2_1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73631.json"