What is CVE-2026-73633?
This CVE is an uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. By reading JSON request bodies into memory without limits, a single request can exhaust the heap and cause a denial of service (DoS). Users are advised to update the plugin configuration or restrict JSON acceptance limits.
Azərbaycanca: Bu CVE, Apache Struts-un JSON plaginində idarə olunmayan resurs istehlakı zəifliyidir. JSON sorğu gövdəsini yaddaşa sərhədsiz oxuyaraq, bir sorğu ilə heap yaddaşını tükəndirib xidmət əngəlinə (DoS) səbəb ola bilər. İstifadəçilərə plagin konfiqurasiyasını yeniləmək və ya JSON qəbul limitlərini məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
In which component of Apache Struts was CVE-2026-73633 discovered?
The vulnerability was discovered in the JSON plugin of Apache Struts.
How can CVE-2026-73633 be exploited to carry out a DoS attack?
By reading JSON request bodies into memory without limits, a single request can exhaust the heap and cause a denial of service (DoS).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.