Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.
History

Sun, 11 Jan 2026 20:30:00 +0000

Type Values Removed Values Added
References

Sun, 11 Jan 2026 13:15:00 +0000

Type Values Removed Values Added
Description Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.
Title Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component
Weaknesses CWE-112
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-01-11T20:04:11.757Z

Reserved: 2025-12-19T06:50:08.538Z

Link: CVE-2025-68493

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-11T13:15:45.610

Modified: 2026-01-11T20:15:45.897

Link: CVE-2025-68493

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.