A vulnerability was found in Apache Struts up to 2.3.37/2.5.33/6.10.0/7.2.1. It has been rated as problematic. This vulnerability affects unknown code of the component JSON plugin. This manipulation causes resource consumption.

The identification of this vulnerability is CVE-2026-73633. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is advised.