TL;DR
The Apache Struts team has fixed four Apache Struts vulnerabilities in Struts 7.4.0 and 6.12.0. The most serious, CVE-2026-104711, allows OGNL injection that may lead to remote code execution in apps using the legacy RESTful action mapper. The other three cause denial of service or leak data between users.
Tired of noisy Apache CVE feeds? Set your own EPSS/CVSS alert threshold.
Try free for 14 daysWhy It Matters
These Apache Struts vulnerabilities matter because Struts still runs many long-lived Java web applications. Moreover, two of the affected branches, 2.3.x and 2.5.x, are end-of-life and will get no fix. Apache rates the REST plugin flaw “Important” and the other three “Moderate.”
So far, no exploitation in the wild or public proof-of-concept has been confirmed for any of these flaws.
How the Attacks Work
OGNL Injection (CVE-2026-104711)
If an app uses the legacy RESTful action mapper, “a crafted request can inject an OGNL expression that may lead to remote code execution,” the advisory warns. However, apps using the default mapper, the restful2 mapper or the REST plugin are safe. Struts 7 is only exposed when its OGNL allowlist is turned off.
REST Plugin DoS (CVE-2026-104713)
The REST plugin reads request bodies into memory “without any bound on how much will be accepted.” As a result, one large request can exhaust the heap. Unlike earlier bugs S2-072 and S2-073, this one works in the default configuration.
BigDecimal Response Expansion (CVE-2026-104712)
When a request parameter binds to a BigDecimal property and renders through the tag library, the response can grow “many orders of magnitude larger than the request.” Low-volume traffic can then saturate CPU and bandwidth.
Shared Formatter Data Leak (CVE-2026-104714)
Struts reuses one date and time formatter across concurrent requests. Consequently, “a value belonging to one user can appear in another user’s response.” No malicious request is needed; ordinary traffic triggers it.
Affected Versions
- Struts 7.0.0 through 7.3.0
- Struts 6.0.0 through 6.11.0
- Struts 2.5.x and 2.3.x (end-of-life, no fix)
Exact starting versions differ by flaw. For instance, the BigDecimal bug begins at 2.5.14.
Patch and Mitigation Steps
Upgrade to Struts 7.4.0, or to 6.12.0 on the 6.x line. Teams stuck on older releases have workarounds. Switch away from the legacy RESTful mapper, cap request body size at the proxy, and pre-format dates before passing them to messages.
Apache details each of these Apache Struts vulnerabilities in its security bulletins: Struts bulletin 1, Struts bulletin 2, Struts bulletin 3 and Struts bulletin 4.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!