Apache fixes four Struts flaws, one of them OGNL code execution
EditorialBy TrustList Editorial
Italy's national cyber agency rates three of the four as high severity and tells users to update; Apache itself rates the code-execution bug only Moderate and limits it to one mapper.
About Apache fixes four Struts flaws, one of them OGNL code execution
Apache fixes four Struts flaws, one of them OGNL code execution
5 October 2026: The Apache Struts project has published four security advisories, CVE-2026-104711 to CVE-2026-104714, and says users should move to Struts 7.4.0 or, on the 6.x line, 6.12.0. Italy's national cybersecurity agency, ACN, issued an alert on 6 October describing three of them as high severity.
Not yet independently verified. The ACN alert marks the proof-of-concept and exploitation columns as empty for all three CVEs, and Apache does not report exploitation. We did not read the S2-078 bulletin for the fourth CVE. We will update this when it can be confirmed, and remove this note.
The most serious is CVE-2026-104711 (bulletin S2-075). An OGNL injection in the legacy RESTful action mapper lets a crafted request run code on the server. Apache rates it Moderate because the exposure is narrow. Applications using the default action mapper, the restful2 mapper or the Struts REST plugin are not affected, and Struts 7 is not affected in its default setup, where the OGNL allowlist is switched on. Affected releases run from 2.0.0 to 6.11.0, plus 7.0.0 to 7.3.0 when the allowlist is disabled.
CVE-2026-104712 (S2-076) is a denial of service. If a request parameter is bound to a java.math.BigDecimal property and rendered through the Struts tag library, the response can be many times larger than the request. Apache says a remote attacker needs no login and little bandwidth to exhaust CPU and outbound capacity. Applications that never render such a property are not affected, and neither are the JSON and REST plugins.
CVE-2026-104713 (S2-077) is a second denial of service. The REST plugin reads a request body into memory without a limit. The fixed releases cap it at 2 MB by default, adjustable with the struts.rest.content.maxLength constant. For anyone who cannot upgrade, Apache has no configuration fix inside Struts and suggests enforcing a maximum body size in the reverse proxy or servlet container. The fourth advisory, CVE-2026-104714, concerns a shared message formatter that exposes date and time values across concurrent requests.
Struts 2.3.x and 2.5.x are end of life, and Apache's bulletins list them as affected without a fix. Teams on those lines have to move to 6.12.0 or 7.4.0 rather than wait for a patch. Struts 7.4.0 reached general availability on 2 October.
Company profile on TrustList: Apache Software Foundation
Sources
- Apache Struts: Announcements 2026 (CVE-2026-104711 to 104714, versions 7.4.0 and 6.12.0), 5 October 2026
- Apache Struts: Security Bulletin S2-075, 2 October 2026
- Apache Struts: Security Bulletin S2-077, 2 October 2026
- ACN (CSIRT Italia): Risolte vulnerabilita in Apache Struts, alert AL06/261006, 6 October 2026
Categories & features
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More ItalyThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.