VYPR

Struts JSON plugin

by Apache

CVEs (2)

  • CVE-2026-73633HigAug 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, so a single request can exhaust…

  • CVE-2026-73631MedAug 15, 2026
    risk 0.28cvss 4.3epss 0.00

    Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one request to become observable in another, and configured parsing limits not to be…