HomeDefault status
unaffected
2.0.0 (semver) before 2.2.1
affected
Default status
unaffected
2.2.1 (semver)
affected
Description
Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.
Problem types
CWE-112 Missing XML Validation
Product status
2.0.0 (semver) before 2.2.1
2.2.1 (semver)
References
www.openwall.com/lists/oss-security/2026/01/11/2
cwiki.apache.org/confluence/display/WW/S2-069
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.