PT-2026-1915 · Apache · Apache Struts

CVE-2025-68493

·

Published

2025-12-19

·

Updated

2026-08-03

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache Struts versions 2.0.0 through 6.1.0
Description An XML processing flaw exists in the XWork component of Apache Struts, specifically within the unconfigured SAX parser of the DomHelper class. The component fails to properly validate XML configuration, making it susceptible to XML External Entity (XXE) injection. This allows a remote attacker to use crafted XML to read sensitive local files and internal resources, trigger Server-Side Request Forgery (SSRF), or cause a Denial-of-Service (DoS) condition.
Recommendations Upgrade Apache Struts to version 6.1.1. As a temporary workaround, disable external entity processing via JVM properties or a custom SAXParserFactory. Restrict outbound egress traffic to minimize the risk of SSRF and data exfiltration.

Exploit

Fix

DoS

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00379
CVE-2025-68493
GHSA-QCFC-HMRC-59X7

Affected Products

Apache Struts