This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.
Users are recommended to upgrade to version 6.1.1, which fixes the issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qcfc-hmrc-59x7 | Apache Struts 2 is Missing XML Validation |
Fri, 16 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-611 | |
| CPEs | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* |
Tue, 13 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 12 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache struts |
|
| Vendors & Products |
Apache
Apache struts |
Mon, 12 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Sun, 11 Jan 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sun, 11 Jan 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue. | |
| Title | Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component | |
| Weaknesses | CWE-112 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-03-11T15:11:36.575Z
Reserved: 2025-12-19T06:50:08.538Z
Link: CVE-2025-68493
Updated: 2026-01-11T20:04:11.757Z
Status : Modified
Published: 2026-01-11T13:15:45.610
Modified: 2026-03-11T16:16:20.980
Link: CVE-2025-68493
OpenCVE Enrichment
Updated: 2026-01-12T14:36:08Z
Github GHSA