← Back to browse · API

CVE-2025-68493

Severity
HIGH
CVSS
8.1
EPSS
0.37055
Risk score
45.37
CISA KEV
No
PoC
No
Published
2026-01-11
Modified
2026-07-15
First seen
2026-08-07
Aliases
EUVD-2026-1898, GHSA-QCFC-HMRC-59X7
Products
Apache Software Foundation:Apache Struts 2.0.0 <2.2.1, Apache Software Foundation:Apache Struts 2.2.1 ≤6.1.0
Sources
euvd EUVD-2026-1898

Description

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.

References