• PoC PUBLIC

CVE-2026-73633: uncontrolled resource consumption in Apache Software Foundation Apache Struts

Remote unauthenticated actors can force Apache Struts to consume excessive memory by sending specially crafted JSON request bodies to applications that use the optional JSON plugin to populate actions. CVE-2026-73633 affects Struts versions 2.1.8–2.3.37, 2.5.0–2.5.33, 6.0.0–6.10.0 and 7.0.0–7.2.1 when JSON request-body handling is enabled; deployments that do not enable that behavior are not vulnerable. An attacker only needs network access to the affected endpoint and the ability to send large or malformed JSON payloads to trigger heap exhaustion and denial of service.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
7.5HIGH
EPSS
0.00698
CWE
CWE-400
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

High priority: public exploit code exists, so immediately protect internet-facing Struts instances that accept JSON request bodies; disable JSON request-body handling or restrict access until a vendor fix is applied.

What is CVE-2026-73633?

Remote unauthenticated actors can force Apache Struts to consume excessive memory by sending specially crafted JSON request bodies to applications that use the optional JSON plugin to populate actions. CVE-2026-73633 affects Struts versions 2.1.8–2.3.37, 2.5.0–2.5.33, 6.0.0–6.10.0 and 7.0.0–7.2.1 when JSON request-body handling is enabled; deployments that do not enable that behavior are not vulnerable. An attacker only needs network access to the affected endpoint and the ability to send large or malformed JSON payloads to trigger heap exhaustion and denial of service. The weakness is classified as CWE-400 (Uncontrolled Resource Consumption).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Which versions of Apache Software Foundation Apache Struts are affected?

BRANCHAFFECTEDFIXED
2.x2.1.8 – 2.3.37
2.x2.5.0 – 2.5.33
6.x6.0.0 – 6.10.0
7.x7.0.0 – 7.2.1

Is CVE-2026-73633 being exploited?

Public exploit code is available.

How to fix CVE-2026-73633

  1. Disable JSON request-body handling in affected Apache Struts deployments unless explicitly required.
  2. Restrict network exposure to Struts applications and block or rate-limit requests with large JSON bodies at firewalls or API gateways.
  3. Monitor JVM and application logs for rapid heap growth, frequent GC pauses, and out-of-memory errors to detect exploitation attempts.
  4. Apply vendor updates or official mitigations as they are released; follow vendor guidance closely.

Frequently asked questions

Is CVE-2026-73633 being actively exploited?

Public exploit code for CVE-2026-73633 is available, indicating active risk to vulnerable deployments.

Which Apache Struts versions are affected by CVE-2026-73633?

Struts 2.1.8 through 2.3.37, 2.5.0 through 2.5.33, 6.0.0 through 6.10.0, and 7.0.0 through 7.2.1 are affected when the JSON plugin is configured to populate actions from a request body.

Is there a patch for CVE-2026-73633?

No fixed versions are listed in the provided facts; follow vendor guidance and apply official updates or mitigations when they become available.

Does CVE-2026-73633 require authentication?

No, the vulnerability can be triggered without authentication if the application accepts JSON request bodies via the plugin.

References