PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73634 Apache Software Foundation CVE debrief

The CVE-2026-73634 record describes an uncontrolled resource consumption vulnerability in Apache Struts, affecting versions from 6.0.0 through 6.10.0 and from 7.0.0 through 7.2.1. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, allowing a single request to exhaust the heap and deny service to other users. Such endpoints are ordinarily reachable without authentication. The core distribution maps no such endpoint by default; applications that do not collect violation reports are not affected. Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue. This debrief provides an overview of the vulnerability, its impact, and recommended actions for affected users.

Vendor
Apache Software Foundation
Product
Apache Struts
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Apache Struts users, administrators of applications using affected versions, and security teams responsible for monitoring and patching vulnerabilities should be aware of this uncontrolled resource consumption vulnerability. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Affected users should prioritize upgrading to version 6.11.0 or 7.3.0 to address the vulnerability. Security teams should monitor for potential denial-of-service attacks and review compensating controls for exposed systems while remediation is scheduled and verified. Asset owners should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Vulnerability management teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Monitoring and detection teams should check relevant monitoring, detection, and logs for exposed assets that need extra review. Inventory management teams should review affected operator, platform, vulnerability-management, and security-team impact to ensure proper mitigation. Change management teams should rollback changes if necessary and verify remediation. Source tracking should be implemented to monitor for similar vulnerabilities in the future. Compensating controls should be reviewed and implemented if necessary. The goal is to ensure that all stakeholders are aware of the vulnerability and are taking necessary actions to mitigate it. This includes verifying that all affected systems are patched or mitigated, and that monitoring and detection systems are in place to detect potential attacks. Additionally, asset owners should review their asset inventory to ensure that all affected assets are accounted for and properly mitigated. By taking these steps, organizations can reduce the risk associated with this vulnerability and protect their systems from potential attacks. It is also essential to review and update incident response plans to ensure that they are preparedto

Technical summary

An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, allowing a single request to exhaust the heap and deny service to other users. Such endpoints are ordinarily reachable without authentication. The vulnerability affects Apache Struts versions from 6.0.0 through 6.10.0 and from 7.0.0 through 7.2.1. The core distribution maps no such endpoint by default; applications that do not collect violation reports are not affected. Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.

Defensive priority

Apache Struts users should prioritize upgrading to version 6.11.0 or 7.3.0 to address the uncontrolled resource consumption vulnerability.

Recommended defensive actions

  • Upgrade to Apache Struts version 6.11.0 or 7.3.0
  • Review and update affected applications to prevent exploitation
  • Monitor for potential denial-of-service attacks
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record indicates an uncontrolled resource consumption vulnerability in Apache Struts, affecting versions from 6.0.0 through 6.10.0 and from 7.0.0 through 7.2.1. Users are recommended to upgrade to version 6.11.0 or 7.3.0. Evidence is limited to the CVE record and NVD detail. Defenders should verify affected scope, severity, and vendor guidance. The CVE record was published on 2026-08-15T11:16:27.427Z and has not been modified since then.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T11:16:27.427Z and has not been modified since then.