Tuesday, October 6, 2026
Follow on LinkedIn

Critical Apache Struts Vulnerabilities Enables Remote Code Execution Attacks

Four security flaws described in the supplied Apache Struts advisories could expose affected applications to remote code execution, denial-of- service, and unintended data disclosure.

Recommended fixes include Struts 7.4.0 or later, or Struts 6.12.0 or later for organizations using the 6.x maintenance line. The vulnerabilities affect different framework components, so exposure depends on application configuration and functionality.

Three issues carry a Moderate security rating, while an unrestricted request body issue in the REST plugin is rated Important. The supplied material does not establish active exploitation.

CVE-2026-104711 involves OGNL injection in the legacy RESTful action mapper. A crafted request can inject an expression that may lead to remote code execution when an application uses this mapper.

Apache documentation explains that the legacy mapper extracts action names and parameter values from request URLs. Affected releases include Struts 2.0.0 through 2.3.37, 2.5.0 through 2.5.33, and 6.0.0 through 6.11.0. Struts 7.0.0 through 7.3.0 is affected only when the OGNL allowlist is disabled.

Applications using the default mapper, restful2 mapper, or Struts REST plugin are not affected by this specific flaw. Struts 7 retains protection in its default configuration. LeaveSong reported the issue.

CVE-2026-104712 allows small requests to generate disproportionately large responses. Exposure occurs when request parameters populate java.math.BigDecimal properties that are subsequently rendered through the Struts tag library.

Apache Struts Vulnerabilities

An unauthenticated attacker can use sustained, low-volume traffic to consume server CPU and outbound network capacity. Applications using other numeric types, or producing responses through the JSON or REST plugins, are outside the described exposure.

Affected versions are Struts 2.5.14 through 2.5.33, 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0. Reporter 0xCc.Zhang identified the flaw.

A temporary workaround uses a custom BigDecimal converter that bounds scale before rendering. Apache supports application-wide converter registration through struts-conversion.properties in the classpath root.

CVE-2026-104713 affects applications accepting request bodies through the optional REST plugin. The vulnerable implementation reads bodies into memory without a size bound, allowing a single oversized request to exhaust heap memory.

Affected versions span Struts 2.1.8 through 2.3.37, 2.5.0 through 2.5.33, 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0. Researcher n0mi1k reported the issue.

Fixed releases introduce a default limit of 2,097,152 characters. Organizations unable to upgrade should enforce request body limits at the reverse proxy or servlet container. The plugin handles incoming content representations, including XML and JSON.

CVE-2026-104714 concerns shared localized message formatters handling date or time arguments. Concurrent requests can interfere, causing one user’s value to appear in another user’s response or triggering rendering errors.

Reported by n0mi1k, it affects the listed Struts branches through 6.11.0 and 7.3.0. Ordinary concurrent traffic can trigger the problem without malicious input.

Administrators should upgrade affected deployments and review mapper settings, decimal rendering, REST endpoints, and localized messages. Formatting dates before message interpolation provides a temporary workaround for the formatter issue.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

Abinaya
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.
0-Hour Cyber Security Alerts!
Get the latest Cyber security News sent directly to your inbox.

Cyber Security Guide

Latest Cyber News

Expert Talks