← Back

CVE-2025-68493

nvd nist
Published: Jan 11, 2026Modified: Jul 15, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Exploitability: 2.8 / Impact: 5.2
Source: NVD

Description

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.

Affected (3)

Products: Apache: Struts
1 product
Struts
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 2.0.0 to 2.3.37
From 2.5.0 to 2.5.33
From 6.0.0 to 6.1.1

References (5)

Source: security@apache.org
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Timeline

No history available yet.