Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Apache Struts Updates Close RCE, Memory Exhaustion and Data-Leak Flaws
Apache Struts Updates Close RCE, Memory Exhaustion and Data-Leak Flaws
Read Time:3 Minute, 27 Second

Apache Struts users are being urged to update after maintainers detailed four vulnerabilities affecting different parts of the Java web framework. Depending on configuration and application behavior, the flaws can enable remote code execution, exhaust memory or processing resources, or reveal one user’s formatted data to another.

The recommended destination is Struts 7.4.0 or later. Organizations remaining on the supported 6.x line should install version 6.12.0 or later. The advisories do not establish that any of the issues are being exploited in the wild, but internet-facing Struts applications deserve prompt review because one flaw can turn a crafted request into code execution.

Legacy mapper creates an OGNL injection path

CVE-2026-104711 affects the legacy RESTful action mapper. A malicious request can place an Object-Graph Navigation Language expression into values derived from the URL, potentially allowing code to run on the server. The vulnerable ranges are Struts 2.0.0 through 2.3.37, 2.5.0 through 2.5.33, and 6.0.0 through 6.11.0.

Struts 7.0.0 through 7.3.0 is exposed only when its OGNL allowlist has been disabled. The default mapper, the restful2 mapper and the Struts REST plugin are not affected by this particular defect. That distinction is important: teams should confirm the mapper actually configured in production instead of assuming every Struts deployment has identical risk.

Two denial-of-service conditions target different resources

CVE-2026-104712 lets a small request provoke a disproportionately large response when parameters populate java.math.BigDecimal properties that are rendered with the Struts tag library. Repeated low-volume requests could consume CPU and outbound bandwidth. Applications using other numeric types or returning content through the JSON or REST plugins are outside the described exposure.

The affected versions are 2.5.14 through 2.5.33, 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0. If an immediate upgrade is impossible, a custom BigDecimal converter can restrict scale before values are rendered, but that measure should be treated as temporary.

CVE-2026-104713 involves the optional REST plugin and carries the highest rating of the four, classified as Important. The vulnerable code reads request bodies into memory without enforcing a size ceiling. One oversized XML or JSON submission can therefore consume the Java heap and make the service unavailable. Fixed versions impose a default maximum of 2,097,152 characters.

This issue reaches back to Struts 2.1.8 and affects the relevant branches through 2.3.37, 2.5.33, 6.11.0 and 7.3.0. Reverse proxies or servlet containers can enforce request-body limits for organizations that cannot patch immediately, though defense at the edge should not replace the framework fix.

Shared formatter can mix data between users

CVE-2026-104714 concerns shared localized message formatters processing date or time arguments. Concurrent requests can interfere with one another, causing a value belonging to one request to appear in another response or producing rendering errors. Unlike the other issues, ordinary traffic may trigger the race without hostile input.

The defect affects listed Struts branches through 6.11.0 and 7.3.0. Formatting dates before inserting them into localized messages can reduce exposure until upgrades are complete.

Practical response for Struts administrators

Security teams should first inventory externally reachable Struts applications and record their exact versions and plugins. They should then inspect mapper settings, confirm whether OGNL protections were weakened, locate endpoints accepting REST bodies, identify BigDecimal properties rendered by tags and review localized message templates.

  • Upgrade to Struts 7.4.0 or 6.12.0 as the primary remediation.
  • Keep the OGNL allowlist enabled and retire the legacy RESTful action mapper.
  • Apply body-size limits at multiple layers and monitor heap pressure.
  • Review logs for unusual URLs, oversized bodies and repeated requests producing large responses.

Because the flaws depend on separate optional components and coding patterns, patching should be paired with configuration validation. A clean version number reduces the immediate risk, while a component-level inventory helps teams understand which attack paths were actually reachable before the update.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Apache Struts Updates Close RCE, Memory Exhaustion and Data-Leak Flaws, use the discussion on Forum.

>> forum community

Comments

Leave a Reply