---
id: CVE-2025-68493
title: >-
  Missing XML Validation vulnerability in Apache Struts, Apache Struts.


  This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from
  2.2.1 through 6.1.0.


  Users are recommended to upgrade to version 6.1.1, which fixes th…
summary: >-
  Missing XML Validation vulnerability in Apache Struts, Apache Struts.


  This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from
  2.2.1 through 6.1.0.


  Users are recommended to upgrade to version 6.1.1, which fixes th…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H'
cwe:
  - CWE-611
  - CWE-112
vendor: apache
product: struts
affected:
  - 'struts >= 2.0.0, <= 2.3.37'
  - 'struts >= 2.5.0, <= 2.5.33'
  - 'struts >= 6.0.0, < 6.1.1'
patched:
  - struts 6.1.1
published: '2026-01-11'
updated: '2026-06-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-68493'
references:
  - url: 'https://cwiki.apache.org/confluence/display/WW/S2-069'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/01/11/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/cve/CVE-2025-68493'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2428559'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68493.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-68493'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-68493'
  - url: 'https://github.com/apache/struts/pull/628'
  - url: 'https://issues.apache.org/jira/browse/WW-5252'
tags:
  - nvd
  - exploit-available
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.45847
epssPercentile: 0.98762
ingestedAt: '2026-06-30T13:26:50.434Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/hsltz/CVE-2025-68493'
  nuclei:
    - CVE-2025-68493
  checkedAt: '2026-09-25T08:20:48.385Z'
exploitAvailable: true
scores:
  nvd: 8.1
  vendor: 7.1
  adp: 8.1
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-01-12T13:52:42.349951Z'
---

## Overview

Missing XML Validation vulnerability in Apache Struts, Apache Struts.

This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.

Users are recommended to upgrade to version 6.1.1, which fixes the issue.

## Affected

- `struts >= 2.0.0, <= 2.3.37`
- `struts >= 2.5.0, <= 2.5.33`
- `struts >= 6.0.0, < 6.1.1`

## Remediation

Upgrade past the affected range:

- `struts 6.1.1`

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat Fuse 7 · no fix planned: Red Hat Fuse 7 · updated 2026-09-12 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-68493.json)
