Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.
Source: NVD ↗ · CISA KEV Catalog ↗