CVE-2026-73631
Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one request to become observable in another, and configured parsing limits not to be enforced as intended. Populating actions from a JSON request body is not enabled by default; applications that do not use the JSON plugin are not affected. This issue affects Apache Struts: 7.2.1. Users are recommended to upgrade to version 7.3.0, which fixes the issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.26%
- CWE
- CWE-567
- Published
- 2026-08-15
- Last modified
- 2026-08-17
Affected products
- Apache Software Foundation Apache Struts
Weakness type
Related vulnerabilities
- CVE-2026-79962 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79969 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79973 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-73632 — Apache Struts: Shared serialization state in the JSON plugin
- CVE-2026-48708 — OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination
- CVE-2026-46693 — ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking
- CVE-2025-48908 — Ability Auto Startup service vulnerability in the foundation process...
- CVE-2023-44374 — A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All...