This is an automated email from the ASF dual-hosted git repository.

asf-gitbox-commits pushed a commit to branch asf-staging
in repository https://gitbox.apache.org/repos/asf/struts-site.git


The following commit(s) were added to refs/heads/asf-staging by this push:
     new 9ef2f7c48 Updates stage by Jenkins
9ef2f7c48 is described below

commit 9ef2f7c48c7f316f5f17cf133d65ab4835e800bf
Author: jenkins <[email protected]>
AuthorDate: Fri Aug 14 07:15:16 2026 +0000

    Updates stage by Jenkins
---
 content/announce-2026.html | 74 ++++++++++++++++++++++++++++++++++++++++++++++
 content/index.html         | 20 ++++++++-----
 2 files changed, 86 insertions(+), 8 deletions(-)

diff --git a/content/announce-2026.html b/content/announce-2026.html
index 008bcaba6..c5cfc9d58 100644
--- a/content/announce-2026.html
+++ b/content/announce-2026.html
@@ -157,6 +157,80 @@
   Skip to: <a href="announce-2025">Announcements - 2025</a>
 </p>
 
+<h4 id="a20260814">14 August 2026 - CVE-2026-73631: Shared parsing state in 
the JSON plugin</h4>
+
+<p>The Apache Struts group recommends upgrading to Apache Struts version 7.3.0 
to mitigate potential security
+vulnerability when populating actions from a JSON request body with the
+<a href="https://struts.apache.org/plugins/json/";>JSON plugin</a>. Only Struts 
7.2.1 is affected.</p>
+
+<blockquote>
+  <p>Please read the Security Bulletin <a 
href="https://cwiki.apache.org/confluence/display/WW/S2-070";>S2-070</a> to find 
more
+details about this security vulnerability</p>
+</blockquote>
+
+<p><strong>All developers are strongly advised to perform this 
upgrade.</strong></p>
+
+<p>You can download the latest version from our <a 
href="download.cgi#struts-ga">download</a> page.</p>
+
+<h4 id="a20260814-s2071">14 August 2026 - CVE-2026-73632: Shared serialization 
state in the JSON plugin</h4>
+
+<p>The Apache Struts group recommends upgrading to Apache Struts version 7.3.0 
to mitigate potential security
+vulnerability when using the SMD / JSON-RPC support of the
+<a href="https://struts.apache.org/plugins/json/";>JSON plugin</a>. Only Struts 
7.2.1 is affected.</p>
+
+<blockquote>
+  <p>Please read the Security Bulletin <a 
href="https://cwiki.apache.org/confluence/display/WW/S2-071";>S2-071</a> to find 
more
+details about this security vulnerability</p>
+</blockquote>
+
+<p><strong>All developers are strongly advised to perform this 
upgrade.</strong></p>
+
+<p>You can download the latest version from our <a 
href="download.cgi#struts-ga">download</a> page.</p>
+
+<h4 id="a20260814-s2072">14 August 2026 - CVE-2026-73633: Unbounded read of a 
JSON request body</h4>
+
+<p>The Apache Struts group recommends upgrading to Apache Struts version 7.3.0 
or 6.11.0 to mitigate potential security
+vulnerability when populating actions from a JSON request body with the
+<a href="https://struts.apache.org/plugins/json/";>JSON plugin</a>.</p>
+
+<blockquote>
+  <p>Please read the Security Bulletin <a 
href="https://cwiki.apache.org/confluence/display/WW/S2-072";>S2-072</a> to find 
more
+details about this security vulnerability</p>
+</blockquote>
+
+<p><strong>All developers are strongly advised to perform this 
upgrade.</strong></p>
+
+<p>You can download the latest version from our <a 
href="download.cgi#struts-ga">download</a> page.</p>
+
+<h4 id="a20260814-s2073">14 August 2026 - CVE-2026-73634: Unbounded read of a 
Content Security Policy violation report</h4>
+
+<p>The Apache Struts group recommends upgrading to Apache Struts version 7.3.0 
or 6.11.0 to mitigate potential security
+vulnerability in applications that expose an endpoint collecting Content 
Security Policy violation reports.</p>
+
+<blockquote>
+  <p>Please read the Security Bulletin <a 
href="https://cwiki.apache.org/confluence/display/WW/S2-073";>S2-073</a> to find 
more
+details about this security vulnerability</p>
+</blockquote>
+
+<p><strong>All developers are strongly advised to perform this 
upgrade.</strong></p>
+
+<p>You can download the latest version from our <a 
href="download.cgi#struts-ga">download</a> page.</p>
+
+<h4 id="a20260814-s2074">14 August 2026 - CVE-2026-73635: Unbounded growth of 
localized-text caches driven by the request locale</h4>
+
+<p>The Apache Struts group recommends upgrading to Apache Struts version 7.3.0 
or 6.11.0 to mitigate potential security
+vulnerability affecting <a 
href="https://struts.apache.org/core-developers/localization";>localized-text</a>
 lookups when no fixed
+locale is configured.</p>
+
+<blockquote>
+  <p>Please read the Security Bulletin <a 
href="https://cwiki.apache.org/confluence/display/WW/S2-074";>S2-074</a> to find 
more
+details about this security vulnerability</p>
+</blockquote>
+
+<p><strong>All developers are strongly advised to perform this 
upgrade.</strong></p>
+
+<p>You can download the latest version from our <a 
href="download.cgi#struts-ga">download</a> page.</p>
+
 <h4 id="a20260801">1 August 2026 - Apache Struts version 7.3.0 General 
Availability</h4>
 
 <p>The Apache Struts group is pleased to announce that Apache Struts version 
7.3.0 is available as a “General Availability”
diff --git a/content/index.html b/content/index.html
index 9f092c163..8bb8895e5 100644
--- a/content/index.html
+++ b/content/index.html
@@ -195,13 +195,17 @@
     </div>
     <div class="row">
       <div class="column col-md-4">
-        <h2>CVE-2025-68493: XXE vulnerability in XWork component</h2>
+        <h2>Security Bulletins S2-070 to S2-074</h2>
         <p>
-          Upgrade to at least Apache Struts 6.1.1 to mitigate the 
vulnerability.
+          Upgrade to Apache Struts 7.3.0 or 6.11.0 to mitigate the 
vulnerabilities.
         </p>
         <p>
-          Read more in the <a href="announce-2026#a20260111">Announcement</a> 
or in
-          the Security Bulletin <a 
href="https://cwiki.apache.org/confluence/display/WW/S2-069";>S2-069</a>
+          Read more in the <a href="announce-2026#a20260814">Announcements</a> 
or in
+          the Security Bulletins <a 
href="https://cwiki.apache.org/confluence/display/WW/S2-070";>S2-070</a>,
+          <a 
href="https://cwiki.apache.org/confluence/display/WW/S2-071";>S2-071</a>,
+          <a 
href="https://cwiki.apache.org/confluence/display/WW/S2-072";>S2-072</a>,
+          <a 
href="https://cwiki.apache.org/confluence/display/WW/S2-073";>S2-073</a> and
+          <a 
href="https://cwiki.apache.org/confluence/display/WW/S2-074";>S2-074</a>
         </p>
       </div>
       <div class="column col-md-4">
@@ -213,13 +217,13 @@
         </p>
       </div>
       <div class="column col-md-4">
-        <h2>CVE-2025-64775 File leak in multipart request processing causes 
disk exhaustion (DoS)</h2>
+        <h2>CVE-2025-68493: XXE vulnerability in XWork component</h2>
         <p>
-          Upgrade to Apache Struts 6.8.0 or 7.1.1 to mitigate the 
vulnerability.
+          Upgrade to at least Apache Struts 6.1.1 to mitigate the 
vulnerability.
         </p>
         <p>
-          Read more in the <a href="announce-2025#a20251201">Announcement</a> 
or in
-          the Security Bulletin <a 
href="https://cwiki.apache.org/confluence/display/WW/S2-068";>S2-068</a>
+          Read more in the <a href="announce-2026#a20260111">Announcement</a> 
or in
+          the Security Bulletin <a 
href="https://cwiki.apache.org/confluence/display/WW/S2-069";>S2-069</a>
         </p>
       </div>
     </div>

Reply via email to