PT-2026-1915 · Apache · Apache Struts
CVE-2025-68493
·
Published
2025-12-19
·
Updated
2026-08-03
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Apache Struts versions 2.0.0 through 6.1.0
Description
An XML processing flaw exists in the XWork component of Apache Struts, specifically within the unconfigured SAX parser of the
DomHelper class. The component fails to properly validate XML configuration, making it susceptible to XML External Entity (XXE) injection. This allows a remote attacker to use crafted XML to read sensitive local files and internal resources, trigger Server-Side Request Forgery (SSRF), or cause a Denial-of-Service (DoS) condition.Recommendations
Upgrade Apache Struts to version 6.1.1.
As a temporary workaround, disable external entity processing via JVM properties or a custom
SAXParserFactory.
Restrict outbound egress traffic to minimize the risk of SSRF and data exfiltration.Exploit
Fix
DoS
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Struts