Follow @Openwall on Twitter for new release announcements and other news
[<prev] [day] [month] [year] [list]
Message-ID: <092d7ffa-d71b-22c4-2014-ce6c21cec8e3@apache.org>
Date: Sun, 11 Jan 2026 11:40:53 +0000
From: Lukasz Lenart <lukaszlenart@...che.org>
To: oss-security@...ts.openwall.com
Subject: CVE-2025-68493: Apache Struts: XXE vulnerability in outdated XWork component

Severity: important 

Affected versions:

- Apache Struts (com.opensymphony:xwork) 2.0.0 before 2.2.1
- Apache Struts (org.apache.struts.xwork:xwork-core) 2.2.1 through 6.1.0

Description:

Missing XML Validation vulnerability in Apache Struts, Apache Struts.

This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.

Users are recommended to upgrade to version 6.1.1, which fixes the issue.

References:

https://cwiki.apache.org/confluence/display/WW/S2-069
https://struts.apache.org/
https://www.cve.org/CVERecord?id=CVE-2025-68493

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.