What is CVE-2026-73634?
An uncontrolled resource consumption vulnerability in Apache Struts allows a single crafted request to exhaust heap memory by reading unbounded Content Security Policy violation reports into memory, potentially causing denial of service. Affected endpoints should be secured with input limits and the application updated as soon as a patch is available.
Azərbaycanca: Bu, Apache Struts-də nəzarətsiz resurs istehlakı zəifliyidir. Content Security Policy pozuntu hesabatlarını toplayan xüsusi uç nöqtəsi daxil olan məlumatı limit olmadan yaddaşa yükləyir, bu da tək bir sorğu ilə yaddaşın tükənməsinə və xidmətin dayanmasına səbəb ola bilər. Təsirə məruz qalan sistem dərhal yenilənməli və ya müvafiq təhlükəsizlik konfiqurasiyaları tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
What specific functionality in Apache Struts does CVE-2026-73634 target?
The vulnerability targets a specific endpoint that collects Content Security Policy violation reports.
What outcome can an attack exploiting this vulnerability cause?
It can exhaust heap memory and cause denial of service with a single request.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.