CVE-2026-73634

Source
https://cve.org/CVERecord?id=CVE-2026-73634
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73634.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-73634
Published
2026-08-15T10:37:37Z
Modified
2026-08-20T03:55:10Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Apache Struts: Unbounded read of a Content Security Policy violation report
Details

Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, so a single request can exhaust the heap and deny service to other users. Such endpoints are ordinarily reachable without authentication. The core distribution maps no such endpoint by default; applications that do not collect violation reports are not affected.

This issue affects Apache Struts: from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1.

Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.

Database specific
{
    "cna_assigner": "apache",
    "cwe_ids": [
        "CWE-400"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73634.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "6.0.0"
                },
                {
                    "last_affected": "6.10.0"
                },
                {
                    "introduced": "7.0.0"
                },
                {
                    "last_affected": "7.2.1"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "6.0.0"
                },
                {
                    "fixed": "6.10.0"
                },
                {
                    "introduced": "7.0.0"
                },
                {
                    "fixed": "7.2.1"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/apache/struts

Affected ranges

Type
GIT
Repo
https://github.com/apache/struts
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "6.0.0"
        },
        {
            "fixed": "6.11.0"
        },
        {
            "introduced": "7.0.0"
        },
        {
            "fixed": "7.3.0"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

Other
STRUTS_6_0_0
STRUTS_6_0_1
STRUTS_6_0_2
STRUTS_6_0_3
STRUTS_6_1_0
STRUTS_6_1_1
STRUTS_6_2_0
STRUTS_6_3_0
STRUTS_6_3_0_1
STRUTS_6_4_0
STRUTS_6_5_0
STRUTS_6_6_0
STRUTS_6_6_1
STRUTS_6_7_0
STRUTS_6_7_1
STRUTS_6_7_2
STRUTS_6_7_3
STRUTS_6_7_4
STRUTS_6_8_0
STRUTS_7_0_0
STRUTS_7_0_1
STRUTS_7_0_2
STRUTS_7_0_3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73634.json"