What is CVE-2026-73635?
A resource allocation without limits vulnerability has been identified in Apache Struts. When no fixed locale is configured, an unauthenticated remote attacker can cause excessive growth of the framework's internal localized-text caches through a crafted request. Upgrading Apache Struts to the latest version is recommended to mitigate this issue.
Azərbaycanca: Apache Struts-da resursların limitsiz alokasiyası zəifliyi aşkarlanıb. Sabit lokal konfiqurasiya edilmədikdə, uzaqdan autentifikasiya olunmamış hücumçu daxil olan sorğu vasitəsilə daxili lokal mətn keşlərinin həddən artıq böyüməsinə səbəb ola bilər. Bu zəifliyi aradan qaldırmaq üçün Apache Struts-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
What component of Apache Struts is affected by CVE-2026-73635?
The vulnerability causes unlimited growth of the framework's internal localized-text caches when no fixed locale is configured.
Does exploiting CVE-2026-73635 require the attacker to be authenticated?
No, an unauthenticated remote attacker can exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.