Apache Struts: Four Vulnerabilities Disclosed Together on October 5, 2026
Key findings • Four Apache Struts vulnerabilities disclosed on October 5, 2026, including race condition, resource exhaustion, and EL injection. • CVE-2026-104714: Race condition in shared re…

Key findings
- Four Apache Struts vulnerabilities disclosed on October 5, 2026, including race condition, resource exhaustion, and EL injection.
- CVE-2026-104714: Race condition in shared resource usage during localized message formatting.
- CVE-2026-104713: REST plugin vulnerable to memory exhaustion via unbounded request body reads.
- CVE-2026-104712: Amplification vulnerability allows responses vastly larger than requests via BigDecimal rendering.
- CVE-2026-104711: Potential RCE via OGNL expression injection in legacy RESTful action mapper.
On October 5, 2026, a batch of four vulnerabilities was disclosed for Apache Struts, a popular open-source framework for developing Java web applications. These vulnerabilities, all disclosed on the same day, highlight distinct weaknesses within the framework, including race conditions, resource exhaustion, amplification attacks, and expression language injection. The collective impact ranges from denial of service to potential remote code execution, underscoring the need for prompt attention from administrators and developers using Apache Struts.
One of the disclosed vulnerabilities, CVE-2026-104714, is a race condition flaw stemming from improper synchronization when using shared resources. Specifically, when a localized message formats a date or time argument, the formatter is retained for that message by the application-wide text provider. This shared resource is then used by concurrently served requests without proper isolation, potentially leading to unpredictable behavior and security issues.
CVE-2026-104713 addresses an allocation of resources without limits or throttling vulnerability within the Apache Struts REST plugin. In this scenario, a request body is read into memory without any bound on the amount that can be accepted. Consequently, a single malicious request can trigger the server to allocate an excessive amount of memory, potentially exhausting the Java heap and leading to a denial of service for legitimate users.
Another vulnerability, CVE-2026-104712, is an asymmetric resource consumption or amplification vulnerability. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property and subsequently rendered through the Struts tag library, the framework can generate a response that is orders of magnitude larger than the initial request. This amplification can be exploited to overwhelm network resources or the server itself.
Finally, CVE-2026-104711 presents an improper neutralization of special elements used in an expression language statement, commonly known as Expression Language Injection. If an application is configured to use the legacy RESTful action mapper, a specially crafted request can inject an OGNL expression. This injection could potentially lead to the execution of arbitrary code on the server, posing a significant remote code execution risk.
The disclosure of these four vulnerabilities on a single day indicates a concentrated release of security information concerning Apache Struts. While the input does not specify whether patches are immediately available or if any of these vulnerabilities are being actively exploited in the wild, the nature of these flaws—particularly the potential for remote code execution and denial of service—warrants immediate review and mitigation by all users of the Apache Struts framework. Administrators should consult official Apache Struts advisories for specific version information and recommended patching or mitigation strategies.
This batch of vulnerabilities serves as a critical reminder for developers and organizations relying on Apache Struts to maintain a proactive security posture. Regularly updating the framework to the latest secure versions and carefully reviewing application configurations, especially those involving the REST plugin or legacy RESTful action mappers, are essential steps in protecting against these types of threats. Staying informed about security disclosures and applying patches promptly are key to mitigating the risks associated with such vulnerabilities.