Back to search
CVE-2025-68493
Published: Jan 11, 2026
Modified: Mar 11, 2026
PUBLISHED
Description
Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache Struts | affected 2.0.0 - < 2.2.1 |
Apache Software Foundation | Apache Struts | affected 2.2.1 - <= 6.1.0 |
Weaknesses (CWE)
References
https://cwiki.apache.org/confluence/display/WW/S2-069
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now