{"advisories":[{"id":"GHSA-qcfc-hmrc-59x7","source":"ghsa","title":"Apache Struts 2 is Missing XML Validation","url":"https://github.com/advisories/GHSA-qcfc-hmrc-59x7"}],"cve":"CVE-2025-68493","enrichment":{"created":"2026-01-12T14:36:08.180724+00:00","updated":"2026-01-12T14:36:08.180749+00:00","vendors":["apache","apache$PRODUCT$struts"]},"epss":{"score":0.45847},"mitre":{"cpes":[],"created":"2026-01-11T13:05:36.894000+00:00","description":"Missing XML Validation vulnerability in Apache Struts, Apache Struts.\n\nThis issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.\n\nUsers are recommended to upgrade to version 6.1.1, which fixes the issue.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"mitre_repo_path":"cves/2025/68xxx/CVE-2025-68493.json","references":["https://cwiki.apache.org/confluence/display/WW/S2-069"],"title":"Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component","updated":"2026-09-14T12:04:26.312000+00:00","vendors":[],"weaknesses":["CWE-611"]},"nvd":{"cpes":["cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*"],"created":"2026-01-11T13:15:45.610000+00:00","description":"Missing XML Validation vulnerability in Apache Struts, Apache Struts.\n\nThis issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.\n\nUsers are recommended to upgrade to version 6.1.1, which fixes the issue.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":8.1,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2025/CVE-2025-68493.json","references":["http://www.openwall.com/lists/oss-security/2026/01/11/2","https://access.redhat.com/security/cve/CVE-2025-68493","https://bugzilla.redhat.com/show_bug.cgi?id=2428559","https://cwiki.apache.org/confluence/display/WW/S2-069","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68493.json"],"title":null,"updated":"2026-07-15T02:17:50.190000+00:00","vendors":["apache","apache$PRODUCT$struts"],"weaknesses":["CWE-112","CWE-611"]},"opencve":{"changes":[{"created":"2026-01-11T13:15:00+00:00","data":[{"details":{"new":"Missing XML Validation vulnerability in Apache Struts, Apache Struts.\n\nThis issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.\n\nUsers are recommended to upgrade to version 6.1.1, which fixes the issue.","old":null},"type":"description"},{"details":{"new":"Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component","old":null},"type":"title"},{"details":{"added":["CWE-112"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://cwiki.apache.org/confluence/display/WW/S2-069"],"removed":[]},"type":"references"}],"id":"16dcbaee-7972-41e4-af8a-d6f10e02d810"},{"created":"2026-01-11T20:30:00+00:00","data":[{"details":{"added":["http://www.openwall.com/lists/oss-security/2026/01/11/2"],"removed":[]},"type":"references"}],"id":"005a6e94-a6f3-4047-b18e-f44aae73c5dd"},{"created":"2026-01-12T14:15:00+00:00","data":[{"details":{"added":{"cvssV3_1":{"score":8.1,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"2dc2843b-231f-4174-bf3f-ffa257cb60df"},{"created":"2026-01-12T14:45:00+00:00","data":[{"details":["apache","apache$PRODUCT$struts"],"type":"first_time"},{"details":{"added":["apache","apache$PRODUCT$struts"],"removed":[]},"type":"vendors"}],"id":"e98c0076-4bda-4c98-8fcd-b62a1f7677a8"},{"created":"2026-01-13T00:15:00+00:00","data":[{"details":{"added":["https://github.com/apache/struts/pull/628","https://issues.apache.org/jira/browse/WW-5252","https://nvd.nist.gov/vuln/detail/CVE-2025-68493","https://www.cve.org/CVERecord?id=CVE-2025-68493"],"removed":[]},"type":"references"},{"details":{"added":{},"removed":{},"updated":{"threat_severity":{"new":"Important","old":null}}},"type":"metrics"}],"id":"9796d66c-3cf8-4a14-9bd9-04d7bdfcf4c7"},{"created":"2026-01-16T14:45:00+00:00","data":[{"details":{"added":["CWE-611"],"removed":[]},"type":"weaknesses"},{"details":{"added":["cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"}],"id":"3f98790c-6d13-4ba7-9575-95e9590caab4"}],"cpes":{"data":["cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2026-01-11T13:05:36+00:00","provider":"redhat"},"description":{"data":"Missing XML Validation vulnerability in Apache Struts, Apache Struts.\n\nThis issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.\n\nUsers are recommended to upgrade to version 6.1.1, which fixes the issue.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":8.1,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"},"provider":"vulnrichment"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.45847},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":"Important","provider":"redhat"}},"references":{"data":["http://www.openwall.com/lists/oss-security/2026/01/11/2","https://access.redhat.com/security/cve/CVE-2025-68493","https://bugzilla.redhat.com/show_bug.cgi?id=2428559","https://cwiki.apache.org/confluence/display/WW/S2-069","https://github.com/apache/struts/pull/628","https://issues.apache.org/jira/browse/WW-5252","https://nvd.nist.gov/vuln/detail/CVE-2025-68493","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68493.json","https://www.cve.org/CVERecord?id=CVE-2025-68493"],"providers":["mitre","nvd","redhat"]},"title":{"data":"Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component","provider":"mitre"},"updated":{"data":"2026-03-11T16:16:20.980000+00:00","provider":"nvd"},"vendors":{"data":["apache","apache$PRODUCT$struts"],"providers":["nvd","enrichment"]},"weaknesses":{"data":["CWE-112","CWE-611"],"providers":["mitre","nvd","redhat"]}},"redhat":{"cpes":[],"created":"2026-01-11T13:05:36+00:00","description":"No description is available for this CVE.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":7.1,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L"},"threat_severity":"Important"},"redhat_repo_path":"2025/CVE-2025-68493.json","references":["https://cwiki.apache.org/confluence/display/WW/S2-069","https://github.com/apache/struts/pull/628","https://issues.apache.org/jira/browse/WW-5252","https://nvd.nist.gov/vuln/detail/CVE-2025-68493","https://www.cve.org/CVERecord?id=CVE-2025-68493"],"title":"org.apache.struts: Apache Struts: Information disclosure and denial of service via missing XML validation","updated":"2026-01-11T13:05:36+00:00","vendors":[],"weaknesses":["CWE-112"]},"vulnrichment":{"cpes":[],"created":"2026-01-11T13:05:36.894000+00:00","description":"Missing XML Validation vulnerability in Apache Struts, Apache Struts.\n\nThis issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.\n\nUsers are recommended to upgrade to version 6.1.1, which fixes the issue.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":8.1,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":"Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component","updated":"2026-01-12T13:52:54.141000+00:00","vendors":[],"vulnrichment_repo_path":"2025/68xxx/CVE-2025-68493.json","weaknesses":[]}}