Apache Struts 7.4.0 fixes four security flaws
On 5 October 2026 Apache published S2-075 through S2-078 for Struts, covering OGNL injection in the legacy RESTful mapper, BigDecimal response expansion, an unbounded REST body read, and a shared date/time message formatter. Fixes ship in 7.4.0 and 6.12.0. No CVSS scores or CISA KEV listings yet.
Published 5 Oct 2026
What happened
On 5 October 2026 the Apache Struts project published four security announcements for CVE-2026-104711, CVE-2026-104712, CVE-2026-104713, and CVE-2026-104714. The matching bulletins are S2-075, S2-076, S2-077, and S2-078. General Availability releases 7.4.0 and 6.12.0 had already been announced on 2 October 2026 and are the versions Apache recommends for these fixes.
The four issues are different classes of defect. S2-075 is possible remote code execution through OGNL injection in the legacy RESTful action mapper. S2-076 is denial of service from disproportionate BigDecimal response expansion. S2-077 is denial of service from an unbounded REST plugin request body read. S2-078 is concurrent use of a shared message formatter that can disclose another user's date or time value or fail rendering.
Who is affected
Exposure depends on configuration and which features an application uses. S2-075 affects applications configured to use the legacy RESTful action mapper; the default mapper, restful2, and the REST plugin are out of scope, and Struts 7 is affected only when the OGNL allowlist is disabled. S2-076 affects apps that bind request parameters to java.math.BigDecimal and render them through the Struts tag library. S2-077 affects applications that use the optional REST plugin to accept request bodies. S2-078 affects applications whose own localized messages format a date or time argument.
Across the bulletins, Apache names ranges spanning EOL 2.x lines plus 6.0.0 through 6.11.0 and 7.0.0 through 7.3.0, with S2-076 starting at 2.5.14 and S2-077 at 2.1.8 for the REST plugin. Anyone still on those lines who matches the feature conditions above is in scope until they move to 7.4.0 or 6.12.0.
What is confirmed
Apache's announcements and bulletins confirm exactly four CVEs for this release wave, with fixed versions 7.4.0 and 6.12.0. Apache severity ratings are Moderate for S2-075, S2-076, and S2-078, and Important for S2-077. The Version Notes for 7.4.0 and 6.12.0 also confirm a default REST request-body size limit of 2,097,152 characters via struts.rest.content.maxLength, deprecation of the legacy restful and restful2 action mappers, and additional REST body and parameter authorization hardening such as authorizing REST body members by Java member name and tighter @StrutsParameter enforcement. CISA's Known Exploited Vulnerabilities catalog does not list any of the four CVEs as of this draft.
What is not confirmed
As of this draft, NVD returns empty results for all four CVE ids, CVE.org reports that the records do not exist yet, and GitHub Security Advisories returns no GHSA entries. Apache has not published CVSS scores, so ThreatWire does not invent any. No public proof-of-concept repository or advisory-tagged PoC was confirmed for these CVE ids, and neither Apache nor CISA confirms exploitation in the wild. Social posts that collapse the four issues into a single "OGNL and REST DoS" headline are incomplete: BigDecimal response expansion and the shared message formatter are separate bulletins.
What to do
Upgrade to Apache Struts 7.4.0 or later, or to 6.12.0 or later if remaining on the 6.x maintenance line. Prefer migrating off the legacy RESTful action mapper to the REST plugin, as Apache has deprecated those mappers. Until an upgrade is possible, apply the bulletin workarounds that fit your stack: avoid the legacy RESTful mapper for S2-075, bound BigDecimal conversion for S2-076, enforce a maximum request body size ahead of the application for S2-077, and pre-format date or time values for S2-078. After upgrading REST applications, review struts.rest.content.maxLength if legitimate bodies exceed the new 2 MB default, and retest cross-site browser clients against the updated REST interceptor stacks.
Sources: Apache Struts announcements for 5 October 2026, Security Bulletins S2-075 through S2-078, Version Notes 7.4.0 and 6.12.0, NVD queries for each CVE id, the CISA KEV catalog feed, and GitHub Security Advisories queries.