VYPR

Struts JSON plugin

by Apache

CVEs (1)

  • CVE-2026-73633HigAug 14, 2026
    risk 0.49cvss 7.5epss

    Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, so a single request can exhaust…