[Japanese]

JVNDB-2026-000121

Apache Struts 2 vulnerable to resource exhaustion

Overview

Apache Struts 2 provided by The Apache Software Foundation contains the following vulnerability:
  • Allocation of resources without limits or throttling (CWE-770) - CVE-2026-73635
KuniyoshiNoguchi reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 7.5 (High) [IPA Score]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: None
  • Integrity Impact: None
  • Availability Impact: High
CVSS v4 Severity
Base Metrics: 8.7 (High) [IPA Score]
  • Access Vector (AV): Network
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): None
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): None
  • Integrity Impact (VI): None
  • Availability Impact (VA): High
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
Affected Products


Apache Software Foundation
  • Apache Struts 2 versions 6.0.0 through 6.10.0
  • Apache Struts 2 versions 7.0.0 through 7.2.1

Impact

Heap memory may be exhausted, causing the affected device to enter a denial-of-service (DoS) state.
Solution

[Update the software]
The vulnerability has been fixed in the versions 7.3.0 and 6.11.0.
Update the software to the latest version according to the information provided by the developer.

While the vulnerability exists in the following versions, it will not be fixed as they are EOL.
  • Versions 2.0.0 through 2.3.37
  • Versions 2.5.0 through 2.5.33
[Apply workaround]
Applications that configure a fixed locale via the struts.locale constant are not affected.
Vendor Information

Apache Software Foundation
  • The Apache Software Foundation : S2-074
CWE (What is CWE?)

  1. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2026-73635
References

  1. JVN : JVN#08517956
Revision History

  • [2026/08/25]
      Web page was published