Unsynchronized Access to Shared Data in a Multithreaded Context Affecting org.apache.struts:struts2-json-plugin package, versions [,7.3.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.26% (18th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHESTRUTS-19350835
  • published27 Aug 2026
  • disclosed15 Aug 2026
  • creditg0w6y

Introduced: 15 Aug 2026

NewCVE-2026-73632  (opens in a new tab)
CWE-567  (opens in a new tab)

How to fix?

Upgrade org.apache.struts:struts2-json-plugin to version 7.3.0 or higher.

Overview

Affected versions of this package are vulnerable to Unsynchronized Access to Shared Data in a Multithreaded Context in the JSON plugin's SMD/JSON-RPC handling. An attacker can access response content intended for another user's session by making concurrent requests, potentially exposing sensitive data.

**Note:**This is only exploitable if the SMD/JSON-RPC handling of the JSON interceptor is enabled.

CVSS Base Scores

version 4.0
version 3.1