CVE-2026-73632
Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become observable in another. Only the SMD / JSON-RPC handling of the JSON interceptor is affected, which is not enabled by default; applications using the json result type are not affected. This issue affects Apache Struts: 7.2.1. Users are recommended to upgrade to version 7.3.0, which fixes the issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.26%
- CWE
- CWE-567
- Published
- 2026-08-15
- Last modified
- 2026-08-17
Affected products
- Apache Software Foundation Apache Struts
Weakness type
Related vulnerabilities
- CVE-2026-79962 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79969 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79973 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-73631 — Apache Struts: Shared parsing state in the JSON plugin
- CVE-2026-48708 — OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination
- CVE-2026-46693 — ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking
- CVE-2025-48908 — Ability Auto Startup service vulnerability in the foundation process...
- CVE-2023-44374 — A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All...