CVE-2026-104714
Shared message formatter leaks date or time across requests
Apache Struts S2-078 says a shared message formatter can let one user's date or time value appear in another user's response, or cause rendering failures. Impact is data disclosure and denial of service. Apache rates it Moderate. Fixed in 7.4.0 and 6.12.0.
- CVSS
- Unknown
- Vector
- Not recorded
- Class
- Info disclosure
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Apache
- Products
- Apache Struts
- Affected
- Struts 2.0.0 through 2.3.37 (EOL); 2.5.0 through 2.5.33 (EOL); 6.0.0 through 6.11.0; 7.0.0 through 7.3.0. Applications whose localized messages format no date or time arguments are not affected.
- Fixed
- Struts 7.4.0 or later, or Struts 6.12.0 or later on the 6.x line.
- CWE
- Not recorded
- Published
- 5 Oct 2026
- Updated
- 5 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-104714 is described in Apache Struts Security Bulletin S2-078. Struts renders localized messages through an application-wide text provider that retains the formatter used for each message. Where a message formats a date or time argument, that retained formatter is used by concurrent requests without isolation. Two requests rendering the same message at the same time can interfere: a value belonging to one user can appear in another user's response, or rendering can fail and surface as a server error. Apache lists the impact as disclosure of data and denial of service, with a maximum security rating of Moderate.
Triggering this requires no malicious request; ordinary concurrent traffic is enough. Applications whose localized messages format no date or time arguments are not affected. No message shipped with Struts formats one, so exposure arises only from an application's own message bundles. A message that interpolates a value without applying a date or time format is also unaffected.
Affected ranges named by Apache are Struts 2.0.0 through 2.3.37 (EOL), 2.5.0 through 2.5.33 (EOL), 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0. Upgrade to Struts 7.4.0 or later, or to Struts 6.12.0 or later on the 6.x line. The change is backward compatible. As a workaround, format date or time values before passing them to the message and use a message that interpolates the already-formatted value.
Apache has not published a CVSS score. NVD and CVE.org have no populated record yet, no GHSA was found, and CISA KEV does not list the CVE. No public PoC tagged to this CVE id was confirmed. Exploitation in the wild is not confirmed.