CVE-2025-68493
Missing XML Validation vulnerability in Apache Struts, Apache Struts.
This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0.
Users are recommended to upgrade to version 6.1.1, which fixes the issue.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2025-68493, https://cwiki.apache.org/confluence/display/WW/S2-069, https://github.com/apache/struts, http://www.openwall.com/lists/oss-security/2026/01/11/2
