Several vulnerabilities have been identified in Apache Struts that could lead to severe security risks such as remote code execution, denial-of-service, and unintended data exposure. Organizations using affected versions should consider upgrading to Struts 7.4.0 or later, or Struts 6.12.0 or later for the 6.x line, to mitigate these issues.
Understanding the Vulnerabilities
The discovered issues are present in different components of the Apache Struts framework, and the level of exposure varies based on individual application configurations. Of the identified vulnerabilities, three are rated as Moderate, while a vulnerability in the REST plugin has been deemed Important. There is no evidence of these vulnerabilities being actively exploited at this time.
One significant vulnerability, identified as CVE-2026-104711, involves OGNL injection in the legacy RESTful action mapper. This flaw could allow a crafted request to execute remote code if an application uses this mapper. This vulnerability affects Struts versions 2.0.0 through 2.3.37, 2.5.0 through 2.5.33, and 6.0.0 through 6.11.0. It is also present in versions 7.0.0 through 7.3.0 if the OGNL allowlist feature is disabled. Applications using the default mapper or the REST plugin are not affected.
Potential Impacts and Mitigation Strategies
Another vulnerability, CVE-2026-104712, permits small requests to generate unexpectedly large responses, posing a risk of resource exhaustion. This issue arises when request parameters are used with java.math.BigDecimal properties and rendered via the Struts tag library. Affected versions include Struts 2.5.14 through 2.5.33, 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0. Organizations can temporarily mitigate this by implementing a custom BigDecimal converter.
The CVE-2026-104713 vulnerability affects applications that utilize the optional REST plugin, allowing unbounded memory use from oversized requests. This flaw impacts Struts versions from 2.1.8 to 2.3.37, 2.5.0 to 2.5.33, and 6.0.0 to 6.11.0, including 7.0.0 to 7.3.0. Updates have introduced a default character limit for request bodies, but organizations that cannot update should set their own limits at the server level.
Recommendations and Future Outlook
Another concern, CVE-2026-104714, involves shared localized message formatters for date or time arguments, which may cause data leakage between user requests. This vulnerability affects all versions up to 6.11.0 and 7.3.0. A temporary solution involves formatting dates before message interpolation.
To protect systems, administrators are encouraged to update affected deployments, review configurations, and enforce better security practices. Addressing these vulnerabilities is crucial in safeguarding applications against potential threats and ensuring data protection.
