Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-73635: CWE-770 Allocation of Resources Without Limits or Throttling in Apache Software Foundation Apache StrutsCVE-2026-73635 0 Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause the framework's internal localized-text caches to grow without bound and exhaust the Java heap, denying service to other users. Applications that configure a fixed locale are not affected. This issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1. Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue. Join the discussion | CVE Database V5 | 08/15/2026, 10:38:08 UTC Added: 08/15/2026, 10:57:13 UTC |
CVE-2026-73634: CWE-400 Uncontrolled Resource Consumption in Apache Software Foundation Apache StrutsCVE-2026-73634 0 Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, so a single request can exhaust the heap and deny service to other users. Such endpoints are ordinarily reachable without authentication. The core distribution maps no such endpoint by default; applications that do not collect violation reports are not affected. This issue affects Apache Struts: from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1. Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue. Join the discussion | CVE Database V5 | 08/15/2026, 10:37:37 UTC Added: 08/15/2026, 10:57:13 UTC |
CVE-2026-73632: CWE-567 Unsynchronized Access to Shared Data in a Multithreaded Context in Apache Software Foundation Apache StrutsCVE-2026-73632 0 Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become observable in another. Only the SMD / JSON-RPC handling of the JSON interceptor is affected, which is not enabled by default; applications using the json result type are not affected. This issue affects Apache Struts: 7.2.1. Users are recommended to upgrade to version 7.3.0, which fixes the issue. Join the discussion | CVE Database V5 | 08/15/2026, 10:38:53 UTC Added: 08/15/2026, 10:57:13 UTC |
CVE-2026-73631: CWE-567 Unsynchronized Access to Shared Data in a Multithreaded Context in Apache Software Foundation Apache StrutsCVE-2026-73631 0 Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one request to become observable in another, and configured parsing limits not to be enforced as intended. Populating actions from a JSON request body is not enabled by default; applications that do not use the JSON plugin are not affected. This issue affects Apache Struts: 7.2.1. Users are recommended to upgrade to version 7.3.0, which fixes the issue. Join the discussion | CVE Database V5 | 08/15/2026, 10:38:28 UTC Added: 08/15/2026, 10:57:13 UTC |
CVE-2026-73633: CWE-400 Uncontrolled Resource Consumption in Apache Software Foundation Apache StrutsCVE-2026-73633 0 An uncontrolled resource consumption vulnerability exists in the JSON plugin of Apache Struts. When configured to populate actions from a JSON request body, the plugin reads the entire body into memory without properly limiting the size, potentially exhausting heap memory and causing denial of service. The plugin's configurable JSON input length limit does not effectively bound this behavior. This vulnerability affects specific versions of Apache Struts and is fixed in versions 6.11.0 and 7.3.0. Join the discussion | GCVE Database | 08/14/2026, 13:48:44 UTC Added: 08/14/2026, 16:35:52 UTC |
Showing 1 to 5 of 5 results