{"id":"CVE-2026-73632","title":"Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts","summary":"Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become obs…","severity":"none","cwe":["CWE-567"],"published":"2026-08-15","updated":"2026-08-15","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73632","references":[{"url":"https://cwiki.apache.org/confluence/display/WW/S2-071","label":"security@apache.org"}],"tags":["nvd"],"ingestedAt":"2026-08-16T07:35:43.130Z","epss":0.00262,"epssPercentile":0.18297,"slug":"CVE-2026-73632","body":"## Overview\n\nExposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become observable in another. Only the SMD / JSON-RPC handling of the JSON interceptor is affected, which is not enabled by default; applications using the json result type are not affected.\n\nThis issue affects Apache Struts: 7.2.1.\n\nUsers are recommended to upgrade to version 7.3.0, which fixes the issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}