8.1
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Description
Missing XML Validation vulnerability in Apache Struts, Apache Struts.
This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.
Users are recommended to upgrade to version 6.1.1, which fixes the issue.
This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.
Users are recommended to upgrade to version 6.1.1, which fixes the issue.
Basic Information
ID
CVE-2025-68493
Source
apache
Published
Jan 11, 2026 at 13:05
Modified
Jan 12, 2026 at 13:52
Affected Product
Vendor
Apache Software Foundation
Product
Apache Struts
Version
2.0.0
Affected Versions
Apache Software Foundation Apache Struts 2.0.0
Apache Software Foundation Apache Struts 2.2.1
Apache Software Foundation Apache Struts 2.2.1