Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Apache Struts Flaws Allow Remote Code Execution
October 6, 2026
ASOS Hacked: App Users Receive Malicious Notifications
October 6, 2026
SOC and MSSP Leaders Build Intelligence-Led Threat Monitoring
October 6, 2026
Home/CyberSecurity News/Critical Apache Struts Flaws Allow Remote Code Execution
CyberSecurity News

Critical Apache Struts Flaws Allow Remote Code Execution

Key Takeaways Four new vulnerabilities have been identified in Apache Struts, potentially leading to remote code execution, denial-of-service, and data exposure. Impact varies based on application...

Sarah simpson
Sarah simpson
October 6, 2026 4 Min Read
2 0

Key Takeaways

  • Four new vulnerabilities have been identified in Apache Struts, potentially leading to remote code execution, denial-of-service, and data exposure.
  • Impact varies based on application configuration and Struts components in use.
  • Three flaws are rated “Moderate,” while one in the REST plugin is deemed “Important.”
  • Patches are available in Struts versions 7.4.0+ and 6.12.0+, and immediate upgrades are recommended.

Critical Apache Struts Flaws Allow Remote Code Execution

Recent advisories from Apache have detailed four distinct security vulnerabilities within the Struts framework. These flaws could expose applications to severe risks, including remote code execution, denial-of-service (DoS) attacks, and unauthorized data disclosure. Developers and administrators are urged to review their deployments and apply necessary updates.

Table Of Content

  • Key Takeaways
  • Critical Apache Struts Flaws Allow Remote Code Execution
  • Detailed Vulnerability Breakdown
  • CVE-2026-104711: OGNL Injection in Legacy RESTful Action Mapper
  • CVE-2026-104712: Denial-of-Service via BigDecimal Properties
  • CVE-2026-104713: Unrestricted Request Body Size in REST Plugin
  • CVE-2026-104714: Concurrent Access Issue in Localized Message Formatters
  • What You Should Do

Apache has released patches in Struts version 7.4.0 and later, as well as 6.12.0 and later for those utilizing the 6.x maintenance branch. The specific impact of these vulnerabilities on an application depends on its configuration and the particular Struts components it employs.

While three of the identified issues carry a “Moderate” security rating, a more critical “Important” rating has been assigned to a flaw involving unrestricted request bodies in the REST plugin. There is currently no indication of active exploitation for any of these vulnerabilities.

Detailed Vulnerability Breakdown

CVE-2026-104711: OGNL Injection in Legacy RESTful Action Mapper

This vulnerability stems from an OGNL injection flaw residing within the legacy RESTful action mapper. A specially crafted request has the potential to inject an expression, leading to remote code execution if the application is configured to use this specific mapper.

As Apache documentation explains, the legacy mapper extracts action names and parameter values directly from request URLs. Affected versions include Struts 2.0.0 through 2.3.37, 2.5.0 through 2.5.33, and 6.0.0 through 6.11.0. Struts versions 7.0.0 through 7.3.0 are also vulnerable if the OGNL allowlist has been disabled. Applications leveraging the default mapper, restful2 mapper, or the Struts REST plugin are not susceptible to this particular flaw. Struts 7, in its default configuration, maintains protection against this issue. This vulnerability was reported by LeaveSong.

CVE-2026-104712: Denial-of-Service via BigDecimal Properties

CVE-2026-104712 allows attackers to trigger disproportionately large responses from small requests. This exposure occurs when request parameters are used to populate java.math.BigDecimal properties, which are subsequently rendered through the Struts tag library.

An unauthenticated attacker could exploit this by sending sustained, low-volume traffic, thereby consuming significant server CPU and outbound network capacity, leading to a denial-of-service. Applications that use other numeric types or produce responses via the JSON or REST plugins are not affected by this specific vulnerability. Affected versions span Struts 2.5.14 through 2.5.33, 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0. The flaw was identified by researcher 0xCc.Zhang.

A temporary mitigation involves implementing a custom BigDecimal converter that bounds the scale before rendering. Apache supports application-wide converter registration through struts-conversion.properties located in the classpath root.

CVE-2026-104713: Unrestricted Request Body Size in REST Plugin

CVE-2026-104713 affects applications that accept request bodies through the optional REST plugin. The vulnerable implementation reads incoming request bodies directly into memory without any size constraints. This oversight enables a single, excessively large request to completely exhaust heap memory, resulting in a denial-of-service condition.

Affected versions include Struts 2.1.8 through 2.3.37, 2.5.0 through 2.5.33, 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0. Researcher n0mi1k is credited with reporting this issue. Patched releases now enforce a default limit of 2,097,152 characters. Organizations unable to upgrade immediately should implement request body limits at the reverse proxy or servlet container level. This plugin is responsible for handling various incoming content representations, including XML and JSON.

CVE-2026-104714: Concurrent Access Issue in Localized Message Formatters

CVE-2026-104714 addresses a concurrency issue within shared localized message formatters, particularly when handling date or time arguments. Under concurrent request scenarios, interference can occur, potentially causing one user’s formatted value to appear in another user’s response, or triggering rendering errors. Reported by n0mi1k, this vulnerability impacts Struts branches up to 6.11.0 and 7.3.0. The problem can be triggered by ordinary concurrent traffic and does not require malicious input.

What You Should Do

  • Upgrade Immediately: Update Apache Struts to version 7.4.0 or later, or 6.12.0 or later if you are on the 6.x maintenance branch.
  • Review Mapper Settings: For CVE-2026-104711, ensure you are not using the legacy RESTful action mapper, or verify that the OGNL allowlist is enabled if on Struts 7.0.0-7.3.0.
  • Implement Custom Converters: For CVE-2026-104712, consider implementing a custom BigDecimal converter to bound scale before rendering if an immediate upgrade is not feasible.
  • Enforce Request Body Limits: For CVE-2026-104713, enforce request body size limits at your reverse proxy or servlet container for applications using the REST plugin if you cannot upgrade.
  • Pre-format Dates: As a temporary workaround for CVE-2026-104714, format dates and times before interpolating them into localized messages.
  • Stay Informed: Regularly monitor Apache Struts advisories for further updates and security recommendations.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitSecurity

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

ASOS Hacked: App Users Receive Malicious Notifications

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Iranian Hackers Target Iraqi Critical Infrastructure With Fake Dubai Airports Coding Test
October 6, 2026
Ransomware Hacker Uses AI Coding Assistant to Attack Enterprise Networks
October 6, 2026
Critical Dell SupportAssist CVE-2024-28956 Vulnerability Allows Code Execution
October 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us