[Git][security-tracker-team/security-tracker][master] Add new apache struts issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Aug 16 06:16:01 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a2879bca by Salvatore Bonaccorso at 2026-08-16T07:15:33+02:00
Add new apache struts issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,11 +1,15 @@
 CVE-2026-73635 (Allocation of resources without limits or throttling vulnerability in  ...)
-	TODO: check
+	- libstruts1.2-java <removed>
+	NOTE: https://cwiki.apache.org/confluence/display/WW/S2-074
 CVE-2026-73634 (Uncontrolled resource consumption vulnerability in Apache Struts. An a ...)
-	TODO: check
+	- libstruts1.2-java <removed>
+	NOTE: https://cwiki.apache.org/confluence/display/WW/S2-073
 CVE-2026-73632 (Exposure of data element to wrong session vulnerability in the JSON pl ...)
-	TODO: check
+	- libstruts1.2-java <removed>
+	NOTE: https://cwiki.apache.org/confluence/display/WW/S2-071
 CVE-2026-73631 (Exposure of data element to wrong session vulnerability in the JSON pl ...)
-	TODO: check
+	- libstruts1.2-java <removed>
+	NOTE: https://cwiki.apache.org/confluence/display/WW/S2-070
 CVE-2026-19906 (A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This  ...)
 	TODO: check
 CVE-2026-19905 (A weakness has been identified in Jinher OA 1.0. Impacted is an unknow ...)
@@ -4638,7 +4642,8 @@ CVE-2026-73844 (CKAN MCP Server is a tool for querying CKAN open data portals. P
 CVE-2026-73673 (Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated fir ...)
 	NOT-FOR-US: Netis NC63 router
 CVE-2026-73633 (Uncontrolled resource consumption vulnerability in the JSON plugin of  ...)
-	TODO: check
+	- libstruts1.2-java <removed>
+	NOTE: https://cwiki.apache.org/confluence/display/WW/S2-072
 CVE-2026-73630 (SiYuan before v3.7.4 contains an information disclosure vulnerability  ...)
 	NOT-FOR-US: SiYuan
 CVE-2026-73107



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a2879bcaa81398804d34d95237fa94bf359136f1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a2879bcaa81398804d34d95237fa94bf359136f1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260816/aa6ae691/attachment.htm>


More information about the debian-security-tracker-commits mailing list