Resource exhaustion in Apache Struts - CVE-2026-73634
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in an endpoint collecting Content Security Policy violation reports when handling a submitted violation report. A remote attacker can send a specially crafted request with an oversized report body to cause a denial of service.
The core distribution maps no such endpoint by default; only applications that collect violation reports are affected.