CVE-2025-68493
massMissing XML Validation (XXE-class) flaw in Apache Struts 2.0.0 through 6.1.0
CVE-2025-68493 is a missing XML validation flaw (CWE-112) in Apache Struts that also falls under CWE-611, the weakness class for improper restriction of XML external entity references (XXE). The affected ranges span essentially every Struts 2 release, from 2.0.0 before 2.2.1 and from 2.2.1 through 6.1.0, and the flaw is expected to be triggered when Struts-based applications process XML that is not properly validated; the CVSS vector (AV:N/AC:L/PR:N/UI:R/S:U) indicates it is network-reachable by unauthenticated attackers but requires user interaction. A successful attack yields high impact on confidentiality and availability (C:H/I:N/A:H), consistent with disclosure of sensitive data and potential denial of service, with no integrity impact per the score. All organizations running any Struts 2 version from 2.0.0 through 6.1.0 are affected and should upgrade to version 6.1.1, which fixes the issue. No public proof of concept, CISA KEV listing, or confirmed in-the-wild exploitation is currently known, but an EPSS of 43.3% (99th percentile) signals a high probability of exploitation within the next 30 days.
What to do: Upgrade all Apache Struts installations to version 6.1.1 or later; because Struts is frequently bundled inside application artifacts, containers, and dependency trees, inventory which applications ship struts2-core and rebuild/redeploy each one. As interim hardening consistent with the CWE-611 classification, review XML parsing paths in Struts-based applications and restrict or disable XML external entity resolution where feasible. With no public PoC or KEV entry yet but a 43.3% EPSS (99th percentile), prioritize patching and monitor for new advisories, proofs of concept, or KEV inclusion.
| Apache Struts | 2.0.0 (inclusive) up to but not including 2.2.1 |
| Apache Struts | 2.2.1 (inclusive) through 6.1.0 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.
- Vendors
- apache
- Products
- struts
- Weakness
- CWE-611, CWE-112
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.