|
[Japanese]
|
JVNDB-2026-000121
|
Apache Struts 2 vulnerable to resource exhaustion
|
Apache Struts 2 provided by The Apache Software Foundation contains the following vulnerability:- Allocation of resources without limits or throttling (CWE-770) - CVE-2026-73635
KuniyoshiNoguchi reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V3 Severity: Base Metrics 7.5 (High) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
|
CVSS v4 Severity
Base Metrics: 8.7 (High) [IPA Score]
- Access Vector (AV): Network
- Attack Complexity (AC): Low
- Attack Requirements (AT): None
- Privileges Required (PR): None
- User Interaction (UI): None
Vulnerable System Impact
- Confidentiality Impact (VC): None
- Integrity Impact (VI): None
- Availability Impact (VA): High
Subsequent System Impact
- Confidentiality Impact (SC): None
- Integrity Impact (SI): None
- Availability Impact (SA): None
|
|
Apache Software Foundation
- Apache Struts 2 versions 6.0.0 through 6.10.0
- Apache Struts 2 versions 7.0.0 through 7.2.1
|
|
Heap memory may be exhausted, causing the affected device to enter a denial-of-service (DoS) state.
|
[Update the software]
The vulnerability has been fixed in the versions 7.3.0 and 6.11.0.
Update the software to the latest version according to the information provided by the developer.
While the vulnerability exists in the following versions, it will not be fixed as they are EOL. - Versions 2.0.0 through 2.3.37
- Versions 2.5.0 through 2.5.33
[Apply workaround]
Applications that configure a fixed locale via the struts.locale constant are not affected.
|
Apache Software Foundation
- The Apache Software Foundation : S2-074
|
- No Mapping(CWE-Other) [IPA Evaluation]
|
- CVE-2026-73635
|
- JVN : JVN#08517956
|
- [2026/08/25]
Web page was published
|