CVE-2026-73635
CVE-2026-73635: 2 tracked advisory records across Apache, Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Apache
1 advisory- Advisory severityHigh7.5
High [CVE-2026-73635] Allocation of resources without limits or throttling vulnerability in Apache Struts
CVE-2026-73635Source published Source updated
Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause the framework's internal localized-text caches to grow without bound and exhaust the Java heap, denying service to other users. Applications that configure a fixed locale are not affected. This issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1. Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.
- Affected products in this advisory
- Apache Struts
- Source-reported affected versions
- 2.0.0 through 2.3.37
- 2.5.0 through 2.5.33
- 6.0.0 through 6.10.0
- 7.0.0 through 7.2.1.
1 more entries in the full advisory.
- Source-reported fixed versions
- 6.11.0
- 7.3.0
- Mitigation guidance
- Applications that configure a fixed locale are not affected.
- Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.
Red Hat
1 advisory- Advisory severityHigh7.5
High [CVE-2026-73635] Denial of Service via unbounded localized-text caches
CVE-2026-73635Source published Source updated
Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause the framework's internal localized-text caches to grow without bound and exhaust the Java heap, denying service to other users. Applications that configure a fixed locale are not affected. Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue. This can lead to the exhaustion of Java heap memory, resulting in a Denial of Service (DoS) for other users. An uncontrolled resource consumption flaw exists in the Apache Struts localized-text lookup caching mechanism. An unauthenticated remote attacker can exploit this by…
- Affected products in this advisory
- No product details extracted. Check the source bulletin.
- Source-reported affected versions
- 2.0.0
- 2.3.37
- 2.5.0
- 2.5.33
4 more entries in the full advisory.
- Source-reported fixed versions
- 6.11.0
- 7.3.0
- Mitigation guidance
- Configure a fixed default locale in `struts.xml` by setting the `struts.locale` property (e.g., `<constant name="struts.locale" value="en_US" />`). Alternatively, configure an API gateway or web application firewall (WAF) to sanitize or strip non-standard `Accept-Language` headers before forwarding traffic to the application.
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.