Apache Struts < 7.3.0 Multiple Vulnerabilities (S2-070) (S2-071)

medium Nessus Plugin ID 338628

Synopsis

The Apache Struts install on the remote host is affected by multiple vulnerabilities in the JSON plugin.

Description

The version of Apache Struts installed on the remote host is 7.2.1. It is, therefore, affected by multiple vulnerabilities in the JSON plugin, as referenced in the S2-070 and S2-071 advisories:

- A component of the JSON plugin that holds per-request parsing state could be shared between concurrent requests instead of being used by a single request at a time. Because that state is not isolated, data associated with one request can become observable in another, and configured parsing limits may not be enforced as intended. Only the population of actions from a JSON request body is affected, which is not enabled by default. Applications that do not use the JSON plugin are not affected. (CVE-2026-73631)

- A component of the JSON plugin that holds per-response serialization state could be shared between concurrent requests instead of being used by a single request at a time. Because that state is not isolated, response data associated with one request can become observable in another. Only the SMD / JSON-RPC handling of the JSON interceptor is affected, which is not enabled by default. The json result type is not affected, as a separate writer is used for each request. (CVE-2026-73632)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Apache Struts version 7.3.0 or later. Alternatively, for CVE-2026-73632, disable SMD support on the JSON interceptor as referenced in the vendor's security bulletin.

See Also

https://cwiki.apache.org/confluence/spaces/WW/pages/444334417/S2-070

https://cwiki.apache.org/confluence/spaces/WW/pages/444334419/S2-071

Plugin Details

Severity: Medium

ID: 338628

File Name: struts_S2-070.nasl

Version: 1.2

Type: Local

Agent: windows, macosx, unix

Family: Misc.

Published: 8/21/2026

Updated: 8/21/2026

Configuration: Enable paranoid mode

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2026-73631

CVSS v3

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-73632

Vulnerability Information

CPE: cpe:/a:apache:struts

Required KB Items: Settings/ParanoidReport, Host/OS, installed_sw/Apache Struts

Exploit Ease: No known exploits are available

Patch Publication Date: 8/1/2026

Vulnerability Publication Date: 7/28/2026

Reference Information

CVE: CVE-2026-73631, CVE-2026-73632