Index
Search
Search the public record. Drafts and scheduled notes are not included.
High
news
Apache Struts 7.4.0 fixes four security flaws
On 5 October 2026 Apache published S2-075 through S2-078 for Struts, covering OGNL injection in the legacy RESTful mapper, BigDecimal response expansion, an unbounded REST body read, and a shared date/time message formatter. Fixes ship in 7.4.0 and 6.12.0. No CVSS scores or CISA KEV listings yet.
Published 3h ago
MediumNo PoC
CVE-2026-104711
OGNL injection in the legacy RESTful action mapper
RCE
Published 19h ago
MediumNo PoC
CVE-2026-104712
Disproportionate BigDecimal response expansion (DoS)
DoS
Published 19h ago
HighNo PoC
CVE-2026-104713
Unbounded REST plugin request body read (DoS)
DoS
Published 19h ago
MediumNo PoC
CVE-2026-104714
Shared message formatter leaks date or time across requests
Info disclosure
Published 19h ago