What is CVE-2026-73632?
This vulnerability in Apache Struts' JSON plugin causes per-response serialization state to be shared across concurrent requests, exposing one user's response content to another. It specifically affects the SMD/JSON-RPC handling, and immediate plugin update is recommended.
Azərbaycanca: Apache Struts-in JSON plaginində aşkar edilmiş bu boşluq, eyni vaxtda gələn sorğular arasında serializasiya məlumatlarının səhv sessiyaya ötürülməsinə səbəb olur. Nəticədə, bir istifadəçinin cavab məzmunu digər istifadəçiyə görünə bilər; yalnız SMD/JSON-RPC emalına təsir edir. Təcili olaraq JSON pluginini yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: Apache
FAQ2
Which component of Apache Struts is affected by CVE-2026-73632?
The vulnerability is in the JSON plugin of Apache Struts, specifically affecting SMD/JSON-RPC handling.
What data leakage risk results from this vulnerability?
Because per-response serialization state is shared across concurrent requests, one user's response content can be exposed to another user.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.