{"id":"CVE-2025-68493","title":"Missing XML Validation vulnerability in Apache Struts, Apache Struts.\n\nThis issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.\n\nUsers are recommended to upgrade to version 6.1.1, which fixes th…","summary":"Missing XML Validation vulnerability in Apache Struts, Apache Struts.\n\nThis issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.\n\nUsers are recommended to upgrade to version 6.1.1, which fixes th…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","cwe":["CWE-611","CWE-112"],"vendor":"apache","product":"struts","affected":["struts >= 2.0.0, <= 2.3.37","struts >= 2.5.0, <= 2.5.33","struts >= 6.0.0, < 6.1.1"],"patched":["struts 6.1.1"],"published":"2026-01-11","updated":"2026-06-30","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-68493","references":[{"url":"https://cwiki.apache.org/confluence/display/WW/S2-069","label":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/01/11/2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/security/cve/CVE-2025-68493","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2428559","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68493.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-68493"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68493"},{"url":"https://github.com/apache/struts/pull/628"},{"url":"https://issues.apache.org/jira/browse/WW-5252"}],"tags":["nvd","exploit-available","csaf","vex","red-hat","cve.org"],"epss":0.4334,"epssPercentile":0.98711,"ingestedAt":"2026-06-30T13:26:50.434Z","exploits":{"github":1,"githubRepos":["https://github.com/hsltz/CVE-2025-68493"],"nuclei":["CVE-2025-68493"],"checkedAt":"2026-09-21T15:27:46.620Z"},"exploitAvailable":true,"scores":{"nvd":8.1,"vendor":7.1,"adp":8.1},"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-01-12T13:52:42.349951Z"},"slug":"CVE-2025-68493","body":"## Overview\n\nMissing XML Validation vulnerability in Apache Struts, Apache Struts.\n\nThis issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.\n\nUsers are recommended to upgrade to version 6.1.1, which fixes the issue.\n\n## Affected\n\n- `struts >= 2.0.0, <= 2.3.37`\n- `struts >= 2.5.0, <= 2.5.33`\n- `struts >= 6.0.0, < 6.1.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `struts 6.1.1`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat Fuse 7 · no fix planned: Red Hat Fuse 7 · updated 2026-09-12 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68493.json)","depth":"midnight","depthScore":65,"depthScoreParts":{"impact":44.6,"likelihood":8.7,"exploitation":12,"ransomware":0},"changes":[{"seq":4902,"id":"CVE-2025-68493","ts":1788887215419,"field":"exploit_available","old":"false","new":"true"},{"seq":3785,"id":"CVE-2025-68493","ts":1788886334959,"field":"exploit_available","old":"true","new":"false"},{"seq":2630,"id":"CVE-2025-68493","ts":1788883013192,"field":"exploit_available","old":"false","new":"true"},{"seq":1659,"id":"CVE-2025-68493","ts":1788882417549,"field":"exploit_available","old":"true","new":"false"},{"seq":767,"id":"CVE-2025-68493","ts":1788881850869,"field":"exploit_available","old":"false","new":"true"},{"seq":101,"id":"CVE-2025-68493","ts":1785612527839,"field":"epss","old":"0.22988","new":"0.37055"}]}