PatchSiren cyber security CVE debrief
CVE-2026-73634 Apache Software Foundation CVE debrief
The CVE-2026-73634 record describes an uncontrolled resource consumption vulnerability in Apache Struts, affecting versions from 6.0.0 through 6.10.0 and from 7.0.0 through 7.2.1. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, allowing a single request to exhaust the heap and deny service to other users. Such endpoints are ordinarily reachable without authentication. The core distribution maps no such endpoint by default; applications that do not collect violation reports are not affected. Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue. This debrief provides an overview of the vulnerability, its impact, and recommended actions for affected users.
- Vendor
- Apache Software Foundation
- Product
- Apache Struts
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Apache Struts users, administrators of applications using affected versions, and security teams responsible for monitoring and patching vulnerabilities should be aware of this uncontrolled resource consumption vulnerability. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Affected users should prioritize upgrading to version 6.11.0 or 7.3.0 to address the vulnerability. Security teams should monitor for potential denial-of-service attacks and review compensating controls for exposed systems while remediation is scheduled and verified. Asset owners should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Vulnerability management teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Monitoring and detection teams should check relevant monitoring, detection, and logs for exposed assets that need extra review. Inventory management teams should review affected operator, platform, vulnerability-management, and security-team impact to ensure proper mitigation. Change management teams should rollback changes if necessary and verify remediation. Source tracking should be implemented to monitor for similar vulnerabilities in the future. Compensating controls should be reviewed and implemented if necessary. The goal is to ensure that all stakeholders are aware of the vulnerability and are taking necessary actions to mitigate it. This includes verifying that all affected systems are patched or mitigated, and that monitoring and detection systems are in place to detect potential attacks. Additionally, asset owners should review their asset inventory to ensure that all affected assets are accounted for and properly mitigated. By taking these steps, organizations can reduce the risk associated with this vulnerability and protect their systems from potential attacks. It is also essential to review and update incident response plans to ensure that they are preparedto
Technical summary
An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, allowing a single request to exhaust the heap and deny service to other users. Such endpoints are ordinarily reachable without authentication. The vulnerability affects Apache Struts versions from 6.0.0 through 6.10.0 and from 7.0.0 through 7.2.1. The core distribution maps no such endpoint by default; applications that do not collect violation reports are not affected. Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.
Defensive priority
Apache Struts users should prioritize upgrading to version 6.11.0 or 7.3.0 to address the uncontrolled resource consumption vulnerability.
Recommended defensive actions
- Upgrade to Apache Struts version 6.11.0 or 7.3.0
- Review and update affected applications to prevent exploitation
- Monitor for potential denial-of-service attacks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record indicates an uncontrolled resource consumption vulnerability in Apache Struts, affecting versions from 6.0.0 through 6.10.0 and from 7.0.0 through 7.2.1. Users are recommended to upgrade to version 6.11.0 or 7.3.0. Evidence is limited to the CVE record and NVD detail. Defenders should verify affected scope, severity, and vendor guidance. The CVE record was published on 2026-08-15T11:16:27.427Z and has not been modified since then.
Official resources
-
CVE-2026-73634 CVE record
CVE.org
-
CVE-2026-73634 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T11:16:27.427Z and has not been modified since then.