THE Apache Struts project has released fixes in Struts 7.4.0 and 6.12.0 that address four vulnerabilities. The most serious is CVE-2026-104711, an OGNL injection flaw that could enable remote code execution in apps using the legacy RESTful action mapper; the advisory notes that applications using the default mapper, the restful2 mapper, or the REST plugin are not affected, and that Struts 7 exposure depends on turning off the OGNL allowlist.
Two other issues relate to denial of service or data leakage: CVE-2026-104713 (REST plugin DoS), where reading large request bodies into memory can exhaust heap even under default configuration; CVE-2026-104714 (Shared Formatter Data Leak), where a shared date/time formatter can cause a user's data to appear in another user’s response.
Additionally, CVE-2026-104712 (BigDecimal Response Expansion) can cause a boundless growth in response size when a request parameter binds to a BigDecimal property and renders through the tag library.
Affected versions are Struts 7.0.0–7.3.0 and 6.0.0–6.11.0, with Struts 2.5.x and 2.3.x end-of-life and not receiving fixes. The recommended mitigation is to upgrade to Struts 7.4.0 or 6.12.0 (on the 6.x line). Workarounds include steering away from the legacy RESTful mapper, capping request body size at the proxy, and pre-formatting dates before they reach message rendering. The article notes that, to date, no exploitation in the wild or public PoCs have been confirmed for these flaws.