What is CVE-2026-73631?
CVE-2026-73631 is a vulnerability in the JSON plugin of Apache Struts involving exposure of data to the wrong session. Per-request parsing state can be shared across concurrent requests, potentially allowing one user's data to be observed by another and causing parsing limits to not be enforced as intended. An immediate update to the latest Struts version is strongly recommended.
Azərbaycanca: CVE-2026-73631, Apache Struts-in JSON plaginində aşkarlanmış 'səhv sessiyaya məlumat ötürülməsi' zəifliyidir. Bu boşluq eyni vaxtda gələn sorğular arasında emal vəziyyətinin paylaşılmasına səbəb olur ki, bu da bir istifadəçinin məlumatlarının digərinə görünməsi riskini yaradır. Təcili olaraq Struts-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: Apache
FAQ2
Which component of Apache Struts is affected by CVE-2026-73631?
This vulnerability affects the JSON plugin of Apache Struts.
What is the primary recommendation to mitigate CVE-2026-73631?
An immediate update to the latest version of Apache Struts is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.