https://seclists.org/oss-sec/2026/q1/50: CVE-2025-68493: Apache Struts: XXE vulnerability in outdated XWork component
Published Jan 11, 2026
·Updated
Affected Software
4 affected components
Apache Struts<2.2.1
Apache Struts>=2.2.1<=6.1.0
maven/com.opensymphony/xwork<2.2.1
maven/org.apache.struts.xwork/xwork-core>=2.2.1<=6.1.0
Frequently Asked Questions
1
What is the severity of CVE-2025-68493?
The severity of CVE-2025-68493 is classified as important.
2
Which versions of Apache Struts are affected by CVE-2025-68493?
CVE-2025-68493 affects Apache Struts versions 2.0.0 before 2.2.1 and 2.2.1 through 6.1.0.
3
How do I fix CVE-2025-68493?
To fix CVE-2025-68493, upgrade to Apache Struts version 2.2.1 or later.
4
What type of vulnerability is CVE-2025-68493?
CVE-2025-68493 is an XML External Entity (XXE) vulnerability due to missing XML validation.
5
What component is involved in CVE-2025-68493?
CVE-2025-68493 involves the outdated XWork component in Apache Struts.