VYPR

JSON plugin

by Apache

CVEs (1)

  • CVE-2026-73632MedAug 15, 2026
    risk 0.28cvss 4.3epss 0.00

    Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become observable in another. Only the SMD /…