Skip to content
TrustList
News

Apache fixes four Struts flaws, one of them OGNL code execution

Editorial

By TrustList Editorial

Italy's national cyber agency rates three of the four as high severity and tells users to update; Apache itself rates the code-execution bug only Moderate and limits it to one mapper.

About Apache fixes four Struts flaws, one of them OGNL code execution

Apache fixes four Struts flaws, one of them OGNL code execution

5 October 2026: The Apache Struts project has published four security advisories, CVE-2026-104711 to CVE-2026-104714, and says users should move to Struts 7.4.0 or, on the 6.x line, 6.12.0. Italy's national cybersecurity agency, ACN, issued an alert on 6 October describing three of them as high severity.

Not yet independently verified. The ACN alert marks the proof-of-concept and exploitation columns as empty for all three CVEs, and Apache does not report exploitation. We did not read the S2-078 bulletin for the fourth CVE. We will update this when it can be confirmed, and remove this note.

The most serious is CVE-2026-104711 (bulletin S2-075). An OGNL injection in the legacy RESTful action mapper lets a crafted request run code on the server. Apache rates it Moderate because the exposure is narrow. Applications using the default action mapper, the restful2 mapper or the Struts REST plugin are not affected, and Struts 7 is not affected in its default setup, where the OGNL allowlist is switched on. Affected releases run from 2.0.0 to 6.11.0, plus 7.0.0 to 7.3.0 when the allowlist is disabled.

CVE-2026-104712 (S2-076) is a denial of service. If a request parameter is bound to a java.math.BigDecimal property and rendered through the Struts tag library, the response can be many times larger than the request. Apache says a remote attacker needs no login and little bandwidth to exhaust CPU and outbound capacity. Applications that never render such a property are not affected, and neither are the JSON and REST plugins.

CVE-2026-104713 (S2-077) is a second denial of service. The REST plugin reads a request body into memory without a limit. The fixed releases cap it at 2 MB by default, adjustable with the struts.rest.content.maxLength constant. For anyone who cannot upgrade, Apache has no configuration fix inside Struts and suggests enforcing a maximum body size in the reverse proxy or servlet container. The fourth advisory, CVE-2026-104714, concerns a shared message formatter that exposes date and time values across concurrent requests.

Struts 2.3.x and 2.5.x are end of life, and Apache's bulletins list them as affected without a fix. Teams on those lines have to move to 6.12.0 or 7.4.0 rather than wait for a patch. Struts 7.4.0 reached general availability on 2 October.

Company profile on TrustList: Apache Software Foundation

Sources

Categories & features

  • Italy
  • Java
  • Application Security
  • Vulnerability Management
  • Patch Management

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy