ZeroHour

CVE-2025-68493

mass

Missing XML Validation (XXE-class) flaw in Apache Struts 2.0.0 through 6.1.0

CVSS 3.1
8.1 high
EPSS
43%p99
Published
()
Modified
AI analysis

CVE-2025-68493 is a missing XML validation flaw (CWE-112) in Apache Struts that also falls under CWE-611, the weakness class for improper restriction of XML external entity references (XXE). The affected ranges span essentially every Struts 2 release, from 2.0.0 before 2.2.1 and from 2.2.1 through 6.1.0, and the flaw is expected to be triggered when Struts-based applications process XML that is not properly validated; the CVSS vector (AV:N/AC:L/PR:N/UI:R/S:U) indicates it is network-reachable by unauthenticated attackers but requires user interaction. A successful attack yields high impact on confidentiality and availability (C:H/I:N/A:H), consistent with disclosure of sensitive data and potential denial of service, with no integrity impact per the score. All organizations running any Struts 2 version from 2.0.0 through 6.1.0 are affected and should upgrade to version 6.1.1, which fixes the issue. No public proof of concept, CISA KEV listing, or confirmed in-the-wild exploitation is currently known, but an EPSS of 43.3% (99th percentile) signals a high probability of exploitation within the next 30 days.

What to do: Upgrade all Apache Struts installations to version 6.1.1 or later; because Struts is frequently bundled inside application artifacts, containers, and dependency trees, inventory which applications ship struts2-core and rebuild/redeploy each one. As interim hardening consistent with the CWE-611 classification, review XML parsing paths in Struts-based applications and restrict or disable XML external entity resolution where feasible. With no public PoC or KEV entry yet but a 43.3% EPSS (99th percentile), prioritize patching and monitor for new advisories, proofs of concept, or KEV inclusion.

Affected
Apache Struts2.0.0 (inclusive) up to but not including 2.2.1
Apache Struts2.2.1 (inclusive) through 6.1.0 (inclusive)
Estimated exposure
masshundreds of thousands of deployments worldwide; tens of thousands likely internet-exposed (estimate) — Struts 2 has been a mainstream Java MVC framework for nearly two decades and is bundled inside a large share of enterprise Java applications (its ubiquity was highlighted by the 2017 Equifax Struts breach), so the installed base plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.

Vendors
apache
Products
struts
Weakness
CWE-611, CWE-112
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.