Apache Struts S2-075 to S2-078: OGNL injection in the legacy RESTful action mapper can lead to RCE (CVE-2026-104711), plus REST-plugin heap exhaustion, BigDecimal response blow-up and a cross-user data mix-up; fixed in 7.4.0 / 6.12.0
The Apache Struts project published four security bulletins, S2-075 to S2-078, with CVE records issued on 5 October 2026 (UTC). S2-075 (CVE-2026-104711, rated Moderate by Apache): if an application uses the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote code execution. Applications on the default mapper, the restful2 mapper or the Struts REST plugin are not affected, and Struts 7 is only affected when its OGNL allowlist has been disabled. S2-076 (CVE-2026-104712, Moderate): a request parameter bound to a java.math.BigDecimal property and rendered through the Struts tags can produce a response many orders of magnitude larger than the request, letting an unauthenticated attacker burn CPU and outbound bandwidth with low-volume traffic. S2-077 (CVE-2026-104713, Important): the optional REST plugin reads request bodies into memory with no size limit, so a single oversized request can exhaust the heap; fixed releases add a default limit of 2,097,152 characters. S2-078 (CVE-2026-104714, Moderate): a message formatter shared between concurrent requests can show one user's date or time value in another user's response or cause rendering errors, with no malicious input needed. Reporters: LeaveSong (S2-075), 0xCc.zhang (S2-076), n0mi1k (S2-077, S2-078). Apache gives severity ratings only; no CVSS score has been published, and no exploitation has been reported. Primary: Apache Struts security bulletins; wire: Cyber Security News (6 Oct).
- Product
- Apache Struts 2 framework (legacy RESTful action mapper, REST plugin, tag library type conversion, localized message formatting)
- Versions
- S2-075: 2.0.0–2.3.37 (EOL), 2.5.0–2.5.33 (EOL), 6.0.0–6.11.0, and 7.0.0–7.3.0 only with the OGNL allowlist disabled. S2-076: 2.5.14–2.5.33, 6.0.0–6.11.0, 7.0.0–7.3.0. S2-077: 2.1.8–2.3.37, 2.5.0–2.5.33, 6.0.0–6.11.0, 7.0.0–7.3.0. S2-078: 2.0.0–2.3.37, 2.5.0–2.5.33, 6.0.0–6.11.0, 7.0.0–7.3.0.
- Exploited in Australia?
- unknown
- Patch to
- Upgrade to Struts 7.4.0 or later, or 6.12.0 or later on the 6.x line; 2.3 and 2.5 are end of life, so plan a migration. Until then: move off the legacy RESTful action mapper (default, restful2 or the REST plugin are unaffected) and keep the Struts 7 OGNL allowlist on; cap request body size at the reverse proxy or servlet container for REST endpoints; register a BigDecimal converter that bounds scale before rendering; and format dates before message interpolation.
Primary: Apache Struts — Security Bulletin S2-075 (CVE-2026-104711) · Vendor: Apache Struts — Security Bulletins (S2-075 to S2-078) · CVE: CVE-2026-104711, CVE-2026-104712, CVE-2026-104713, CVE-2026-104714 · Cyber Security News — Critical Apache Struts Vulnerabilities Enables Remote Code Execution Attacks (6 Oct 2026)
