Critical Apache Struts Flaws Allow Remote Code Execution
Key Takeaways Four new vulnerabilities have been identified in Apache Struts, potentially leading to remote code execution, denial-of-service, and data exposure. Impact varies based on application...
Key Takeaways
- Four new vulnerabilities have been identified in Apache Struts, potentially leading to remote code execution, denial-of-service, and data exposure.
- Impact varies based on application configuration and Struts components in use.
- Three flaws are rated “Moderate,” while one in the REST plugin is deemed “Important.”
- Patches are available in Struts versions 7.4.0+ and 6.12.0+, and immediate upgrades are recommended.
Critical Apache Struts Flaws Allow Remote Code Execution
Recent advisories from Apache have detailed four distinct security vulnerabilities within the Struts framework. These flaws could expose applications to severe risks, including remote code execution, denial-of-service (DoS) attacks, and unauthorized data disclosure. Developers and administrators are urged to review their deployments and apply necessary updates.
Table Of Content
- Key Takeaways
- Critical Apache Struts Flaws Allow Remote Code Execution
- Detailed Vulnerability Breakdown
- CVE-2026-104711: OGNL Injection in Legacy RESTful Action Mapper
- CVE-2026-104712: Denial-of-Service via BigDecimal Properties
- CVE-2026-104713: Unrestricted Request Body Size in REST Plugin
- CVE-2026-104714: Concurrent Access Issue in Localized Message Formatters
- What You Should Do
Apache has released patches in Struts version 7.4.0 and later, as well as 6.12.0 and later for those utilizing the 6.x maintenance branch. The specific impact of these vulnerabilities on an application depends on its configuration and the particular Struts components it employs.
While three of the identified issues carry a “Moderate” security rating, a more critical “Important” rating has been assigned to a flaw involving unrestricted request bodies in the REST plugin. There is currently no indication of active exploitation for any of these vulnerabilities.
Detailed Vulnerability Breakdown
CVE-2026-104711: OGNL Injection in Legacy RESTful Action Mapper
This vulnerability stems from an OGNL injection flaw residing within the legacy RESTful action mapper. A specially crafted request has the potential to inject an expression, leading to remote code execution if the application is configured to use this specific mapper.
As Apache documentation explains, the legacy mapper extracts action names and parameter values directly from request URLs. Affected versions include Struts 2.0.0 through 2.3.37, 2.5.0 through 2.5.33, and 6.0.0 through 6.11.0. Struts versions 7.0.0 through 7.3.0 are also vulnerable if the OGNL allowlist has been disabled. Applications leveraging the default mapper, restful2 mapper, or the Struts REST plugin are not susceptible to this particular flaw. Struts 7, in its default configuration, maintains protection against this issue. This vulnerability was reported by LeaveSong.
CVE-2026-104712: Denial-of-Service via BigDecimal Properties
CVE-2026-104712 allows attackers to trigger disproportionately large responses from small requests. This exposure occurs when request parameters are used to populate java.math.BigDecimal properties, which are subsequently rendered through the Struts tag library.
An unauthenticated attacker could exploit this by sending sustained, low-volume traffic, thereby consuming significant server CPU and outbound network capacity, leading to a denial-of-service. Applications that use other numeric types or produce responses via the JSON or REST plugins are not affected by this specific vulnerability. Affected versions span Struts 2.5.14 through 2.5.33, 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0. The flaw was identified by researcher 0xCc.Zhang.
A temporary mitigation involves implementing a custom BigDecimal converter that bounds the scale before rendering. Apache supports application-wide converter registration through struts-conversion.properties located in the classpath root.
CVE-2026-104713: Unrestricted Request Body Size in REST Plugin
CVE-2026-104713 affects applications that accept request bodies through the optional REST plugin. The vulnerable implementation reads incoming request bodies directly into memory without any size constraints. This oversight enables a single, excessively large request to completely exhaust heap memory, resulting in a denial-of-service condition.
Affected versions include Struts 2.1.8 through 2.3.37, 2.5.0 through 2.5.33, 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0. Researcher n0mi1k is credited with reporting this issue. Patched releases now enforce a default limit of 2,097,152 characters. Organizations unable to upgrade immediately should implement request body limits at the reverse proxy or servlet container level. This plugin is responsible for handling various incoming content representations, including XML and JSON.
CVE-2026-104714: Concurrent Access Issue in Localized Message Formatters
CVE-2026-104714 addresses a concurrency issue within shared localized message formatters, particularly when handling date or time arguments. Under concurrent request scenarios, interference can occur, potentially causing one user’s formatted value to appear in another user’s response, or triggering rendering errors. Reported by n0mi1k, this vulnerability impacts Struts branches up to 6.11.0 and 7.3.0. The problem can be triggered by ordinary concurrent traffic and does not require malicious input.
What You Should Do
- Upgrade Immediately: Update Apache Struts to version 7.4.0 or later, or 6.12.0 or later if you are on the 6.x maintenance branch.
- Review Mapper Settings: For CVE-2026-104711, ensure you are not using the legacy RESTful action mapper, or verify that the OGNL allowlist is enabled if on Struts 7.0.0-7.3.0.
- Implement Custom Converters: For CVE-2026-104712, consider implementing a custom BigDecimal converter to bound scale before rendering if an immediate upgrade is not feasible.
- Enforce Request Body Limits: For CVE-2026-104713, enforce request body size limits at your reverse proxy or servlet container for applications using the REST plugin if you cannot upgrade.
- Pre-format Dates: As a temporary workaround for CVE-2026-104714, format dates and times before interpolating them into localized messages.
- Stay Informed: Regularly monitor Apache Struts advisories for further updates and security recommendations.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.