Unsynchronized Access to Shared Data in a Multithreaded Context Affecting org.apache.struts:struts2-json-plugin package, versions [,7.3.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.26% (18th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHESTRUTS-19350821
  • published27 Aug 2026
  • disclosed15 Aug 2026
  • creditg0w6y

Introduced: 15 Aug 2026

NewCVE-2026-73631  (opens in a new tab)
CWE-567  (opens in a new tab)

How to fix?

Upgrade org.apache.struts:struts2-json-plugin to version 7.3.0 or higher.

Overview

Affected versions of this package are vulnerable to Unsynchronized Access to Shared Data in a Multithreaded Context in the JSON plugin due to shared parsing state across concurrent requests. An attacker can access data associated with another user's request or bypass configured parsing limits by sending simultaneous requests that exploit the shared state.

CVSS Base Scores

version 4.0
version 3.1