Resource exhaustion in Apache Struts - CVE-2026-73633
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the JSON plugin when handling a JSON request body to populate actions. A remote attacker can send a specially crafted request with an excessively large JSON body to cause a denial of service.
Only applications configured to populate actions from a JSON request body are vulnerable.