CVE-2026-73635
published 2026-08-15CVE-2026-73635: Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.45%
38.0th percentile
Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause the framework's internal localized-text caches to grow without bound and exhaust the Java heap, denying service to other users. Applications that configure a fixed locale are not affected.
This issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1.
Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | 2.0.0 – 2.3.37 | — |
| apache | struts | 2.5.0 – 2.5.33 | — |
| apache | struts | >= 6.0.0 < 6.11.0 | 6.11.0 |
| apache | struts | >= 7.0.0 < 7.3.0 | 7.3.0 |
| apache_software_foundation | apache_struts | 2.0.0 – 2.3.37 | — |
| apache_software_foundation | apache_struts | 2.5.0 – 2.5.33 | — |
| apache_software_foundation | apache_struts | 6.0.0 – 6.10.0 | — |
| apache_software_foundation | apache_struts | 7.0.0 – 7.2.1 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Allocation of resources without limits or throttling vulnerability in Apache Struts.
ghsa_unreviewed·2026-08-15
CVE-2026-73635 CWE-770 Allocation of resources without limits or throttling vulnerability in Apache Struts.
Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause the framework's internal localized-text caches to grow without bound and exhaust the Java heap, denying service to other users. Applications that configure a fixed locale are not affected.
This issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1.
Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.
VulDB
Apache Struts prior 6.11.0/7.3.0 Localized-Text Cache allocation of resources (WID-SEC-2026-2848)
vuldb·2026-08-15
CVE-2026-73635 [LOW] Apache Struts prior 6.11.0/7.3.0 Localized-Text Cache allocation of resources (WID-SEC-2026-2848)
A vulnerability described as problematic has been identified in Apache Struts. The impacted element is an unknown function of the component Localized-Text Cache. Such manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2026-73635. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
Red Hat
Apache Struts: Apache Struts: Denial of Service via unbounded localized-text caches
vendor_redhat·2026-08-15·CVSS 7.5
CVE-2026-73635 [HIGH] CWE-770 Apache Struts: Apache Struts: Denial of Service via unbounded localized-text caches
Apache Struts: Apache Struts: Denial of Service via unbounded localized-text caches
Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause the framework's internal localized-text caches to grow without bound and exhaust the Java heap, denying service to other users. Applications that configure a fixed locale are not affected.
This issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1.
Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.
A flaw was found in Apache Struts. An unauthentic
No detection rules found.
No public exploits indexed.
2026-08-15
Published