Allocation of Resources Without Limits or Throttling in Apache Struts - CVE-2026-73635
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in localized-text caches when processing requests with attacker-controlled locale values. A remote attacker can send repeated requests using distinct locale values to cause a denial of service.
Only applications that do not configure a fixed locale are affected.