CVE-2026-73634: Apache Struts: Unbounded read of a Content Security Policy violation report

Published Aug 15, 2026
·
Updated

Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, so a single request can exhaust the heap and deny service to other users. Such endpoints are ordinarily reachable without authentication. The core distribution maps no such endpoint by default; applications that do not collect violation reports are not affected.

This issue affects Apache Struts: from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1.

Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.

Affected Software

2 affected components
Apache Struts>=6.0.0<=6.10.0, >=7.0.0<=7.2.1
Apache Struts<6.11.0, <7.3.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache Struts to a version that resolves this vulnerability.

    Fixed in 6.11.0
  2. Upgrade

    Upgrade Apache Struts to a version that resolves this vulnerability.

    Fixed in 7.3.0
  3. Compensating control

    Because the CSP violation-reporting endpoint is ordinarily reachable without authentication, restrict network access to the endpoint so it is not broadly reachable if not required.

Event History

Aug 15, 2026
CVE Published
via MITRE·10:37 AM
Data Sourced
via MITRE·10:37 AM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-73634?

CVE-2026-73634 has a risk rating of 28, indicating a moderate severity vulnerability.

2

How do I fix CVE-2026-73634?

To mitigate CVE-2026-73634, configure your Apache Struts application to limit the size of incoming Content Security Policy violation reports.

3

What impact does CVE-2026-73634 have on my application?

CVE-2026-73634 can lead to uncontrolled resource consumption, potentially exhausting heap memory and causing denial of service.

4

Which versions of Apache Struts are affected by CVE-2026-73634?

CVE-2026-73634 affects all versions of Apache Struts that expose endpoints for collecting Content Security Policy violation reports without proper size limitations.

5

What types of applications are at risk from CVE-2026-73634?

Applications that utilize Apache Struts and collect Content Security Policy violation reports are at risk from CVE-2026-73634.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203