{"api_version":"v1","generated_at":"2026-10-05T23:00:00+00:00","product":{"cve_count":24,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-struts-38214e403866","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache Struts","next_cursor":null,"observations":[{"affected":"7.2.1","affected_versions_present":true,"cve_id":"CVE-2026-73632","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73632","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-17T12:40:45.499Z","patch_url":"https://cwiki.apache.org/confluence/display/WW/S2-071","primary_source":"","published":"2026-08-15T10:38:53.381Z"},{"affected":"7.2.1","affected_versions_present":true,"cve_id":"CVE-2026-73631","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73631","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-17T12:42:11.591Z","patch_url":"","primary_source":"","published":"2026-08-15T10:38:28.497Z"},{"affected":"2.0.0 \u2264 2.3.37; 2.5.0 \u2264 2.5.33; 6.0.0 \u2264 6.10.0; 7.0.0 \u2264 7.2.1","affected_versions_present":true,"cve_id":"CVE-2026-73635","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73635","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-17T12:43:26.618Z","patch_url":"","primary_source":"","published":"2026-08-15T10:38:08.227Z"},{"affected":"6.0.0 \u2264 6.10.0; 7.0.0 \u2264 7.2.1","affected_versions_present":true,"cve_id":"CVE-2026-73634","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73634","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-17T12:44:54.972Z","patch_url":"https://cwiki.apache.org/confluence/display/WW/S2-073","primary_source":"","published":"2026-08-15T10:37:37.892Z"},{"affected":"2.1.8 \u2264 2.3.37; 2.5.0 \u2264 2.5.33; 6.0.0 \u2264 6.10.0; 7.0.0 \u2264 7.2.1","affected_versions_present":true,"cve_id":"CVE-2026-73633","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73633","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-14T14:38:07.397Z","patch_url":"","primary_source":"","published":"2026-08-14T13:48:44.821Z"},{"affected":"Apache Struts: 2.0.0 < 2.2.1, 2.2.1 \u2264 6.1.0","affected_versions_present":true,"cve_id":"CVE-2025-68493","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68493","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T12:04:26.312Z","patch_url":"","primary_source":"","published":"2026-01-11T13:05:36.894Z"},{"affected":"2.0.0 \u2264 6.7.*; 7.0.0 \u2264 7.0.*","affected_versions_present":true,"cve_id":"CVE-2025-66675","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-66675","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-12-10T14:53:13.391Z","patch_url":"","primary_source":"","published":"2025-12-10T09:32:58.536Z"},{"affected":"2.0.0 \u2264 6.7.0; 7.0.0 \u2264 7.0.3","affected_versions_present":true,"cve_id":"CVE-2025-64775","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64775","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-12-01T18:23:17.469Z","patch_url":"","primary_source":"","published":"2025-12-01T16:07:36.573Z"},{"affected":"2.0.0 < 6.4.0","affected_versions_present":true,"cve_id":"CVE-2024-53677","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-53677","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-01-03T12:04:30.841Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/apache-security-advisory-av24-708","primary_source":"","published":"2024-12-11T15:35:43.389Z"},{"affected":"2.0.0 \u2264 2.5.32; 6.0.0 \u2264 6.3.0.1","affected_versions_present":true,"cve_id":"CVE-2023-50164","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-50164","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-03-14T03:55:16.463Z","patch_url":"https://lists.apache.org/thread/yh09b3fkf6vz5d6jdgrlvmg60lfwtqhj","primary_source":"","published":"2023-12-07T08:49:19.853Z"},{"affected":"2.0.0 \u2264 2.5.31; 6.1.2.1 \u2264 6.3.0","affected_versions_present":true,"cve_id":"CVE-2023-41835","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-41835","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-04T19:21:09.564Z","patch_url":"","primary_source":"","published":"2023-12-05T08:37:31.602Z"},{"affected":"\u2264 2.5.30; \u2264 6.1.2","affected_versions_present":true,"cve_id":"CVE-2023-34396","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-34396","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T16:55:30.737Z","patch_url":"","primary_source":"","published":"2023-06-14T07:50:59.730Z"},{"affected":"\u2264 2.5.30; \u2264 6.1.2","affected_versions_present":true,"cve_id":"CVE-2023-34149","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-34149","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T16:55:20.286Z","patch_url":"","primary_source":"","published":"2023-06-14T07:48:54.926Z"},{"affected":"2.0.0 to 2.5.29","affected_versions_present":true,"cve_id":"CVE-2021-31805","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-31805","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T23:10:30.193Z","patch_url":"https://cwiki.apache.org/confluence/display/WW/S2-062","primary_source":"","published":"2022-04-12T15:25:11.000Z"},{"affected":"before 2.3.20","affected_versions_present":true,"cve_id":"CVE-2015-2992","cve_url":"https://cve.blacktree.nl/cve/CVE-2015-2992","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-06T05:32:21.181Z","patch_url":"","primary_source":"","published":"2020-02-27T17:45:34.000Z"},{"affected":"Apache Struts 2.1.1 to 2.5.14.1","affected_versions_present":true,"cve_id":"CVE-2018-1327","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-1327","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-16T23:11:07.229Z","patch_url":"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","primary_source":"","published":"2018-03-27T21:00:00.000Z"},{"affected":"2.5 to 2.5.14","affected_versions_present":true,"cve_id":"CVE-2017-15707","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-15707","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-16T22:01:58.959Z","patch_url":"https://cwiki.apache.org/confluence/display/WW/S2-054","primary_source":"","published":"2017-12-01T16:00:00.000Z"},{"affected":"2.3.7 - 2.3.33; 2.5 - 2.5.12","affected_versions_present":true,"cve_id":"CVE-2017-9804","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-9804","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-17T03:37:30.803Z","patch_url":"http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html","primary_source":"","published":"2017-09-20T17:00:00.000Z"},{"affected":"2.3.7 - 2.3.33; 2.5 - 2.5.12; 2.1.x series","affected_versions_present":true,"cve_id":"CVE-2017-9793","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-9793","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-16T20:12:54.032Z","patch_url":"http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html","primary_source":"","published":"2017-09-20T17:00:00.000Z"},{"affected":"2.0.0 - 2.3.33; 2.5 - 2.5.10.1","affected_versions_present":true,"cve_id":"CVE-2017-12611","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-12611","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-17T01:30:41.845Z","patch_url":"http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html","primary_source":"","published":"2017-09-20T17:00:00.000Z"},{"affected":"2.5 - 2.5.5","affected_versions_present":true,"cve_id":"CVE-2016-8738","cve_url":"https://cve.blacktree.nl/cve/CVE-2016-8738","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-16T20:32:00.228Z","patch_url":"https://struts.apache.org/docs/s2-044.html","primary_source":"","published":"2017-09-20T17:00:00.000Z"},{"affected":"2.3.x before 2.3.31; 2.5.x before 2.5.5","affected_versions_present":true,"cve_id":"CVE-2016-6795","cve_url":"https://cve.blacktree.nl/cve/CVE-2016-6795","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-17T02:33:08.731Z","patch_url":"","primary_source":"","published":"2017-09-20T17:00:00.000Z"},{"affected":"2.3.x prior to 2.3.33; 2.5 to 2.5.10.1","affected_versions_present":true,"cve_id":"CVE-2017-9787","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-9787","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-17T02:47:37.383Z","patch_url":"","primary_source":"","published":"2017-07-13T15:00:00.000Z"},{"affected":"2.5 to 2.5.10.1","affected_versions_present":true,"cve_id":"CVE-2017-7672","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-7672","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-17T01:41:33.467Z","patch_url":"http://struts.apache.org/docs/s2-047.html","primary_source":"","published":"2017-07-13T15:00:00.000Z"}],"source_generated_at":"2026-10-05T06:20:29.126Z","vendor":"Apache Software Foundation"}}
