Fork me on GitHub
Edit on GitHub

Announcements 2026

Skip to: Announcements - 2025

5 October 2026 - CVE-2026-104711: OGNL injection in the legacy RESTful action mapper

The Apache Struts group recommends upgrading to Apache Struts version 7.4.0 or 6.12.0 to mitigate potential security vulnerability in applications configured to use the legacy RESTful action mapper. Struts 7 is affected only when the OGNL allowlist is disabled; it is enabled by default.

Please read the Security Bulletin S2-075 to find more details about this security vulnerability

All developers are strongly advised to perform this upgrade.

You can download the latest version from our download page.

5 October 2026 - CVE-2026-104712: Disproportionate response size when rendering BigDecimal request parameters

The Apache Struts group recommends upgrading to Apache Struts version 7.4.0 or 6.12.0 to mitigate potential security vulnerability in applications that bind request parameters to java.math.BigDecimal properties and render them through the Struts tag library.

Please read the Security Bulletin S2-076 to find more details about this security vulnerability

All developers are strongly advised to perform this upgrade.

You can download the latest version from our download page.

5 October 2026 - CVE-2026-104713: Unbounded request body read in the REST plugin

The Apache Struts group recommends upgrading to Apache Struts version 7.4.0 or 6.12.0 to mitigate potential security vulnerability in applications using the REST plugin.

Please read the Security Bulletin S2-077 to find more details about this security vulnerability

All developers are strongly advised to perform this upgrade.

You can download the latest version from our download page.

5 October 2026 - CVE-2026-104714: Shared message formatter exposes date and time values across concurrent requests

The Apache Struts group recommends upgrading to Apache Struts version 7.4.0 or 6.12.0 to mitigate potential security vulnerability in applications whose localized messages format a date or time argument.

Please read the Security Bulletin S2-078 to find more details about this security vulnerability

All developers are strongly advised to perform this upgrade.

You can download the latest version from our download page.

2 October 2026 - Apache Struts version 7.4.0 General Availability

The Apache Struts group is pleased to announce that Apache Struts version 7.4.0 is available as a “General Availability” release. The GA designation is our highest quality grade.

The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework has been designed to streamline the full development cycle, from building, to deploying, to maintaining applications over time.

Please read the Migration Guide to find more details about how to adopt a new version.

Please read the Version Notes to find more details about performed bug fixes and improvements.

All developers are strongly advised to perform this upgrade.

The 7.x series of the Apache Struts framework has a minimum requirement of the following specification versions: Java 17 and JakartaEE.

Should any issues arise with your use of any version of the Struts framework, please post your comments to the user list, and, if appropriate, file a tracking ticket.

You can download this version from our download page.

2 October 2026 - Apache Struts version 6.12.0 General Availability

The Apache Struts group is pleased to announce that Apache Struts version 6.12.0 is available as a “General Availability” release. The GA designation is our highest quality grade.

The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework has been designed to streamline the full development cycle, from building, to deploying, to maintaining applications over time.

Please read the Version Notes to find more details about performed bug fixes and improvements.

All developers are strongly advised to perform this upgrade.

The 6.x series of the Apache Struts framework has a minimum requirement of the following specification versions: Servlet API 3.1, JSP API 2.1, and Java 8.

Should any issues arise with your use of any version of the Struts framework, please post your comments to the user list, and, if appropriate, file a tracking ticket.

You can download this version from our download page.

14 August 2026 - CVE-2026-73631: Shared parsing state in the JSON plugin

The Apache Struts group recommends upgrading to Apache Struts version 7.3.0 to mitigate potential security vulnerability when populating actions from a JSON request body with the JSON plugin. Only Struts 7.2.1 is affected.

Please read the Security Bulletin S2-070 to find more details about this security vulnerability

All developers are strongly advised to perform this upgrade.

You can download the latest version from our download page.

14 August 2026 - CVE-2026-73632: Shared serialization state in the JSON plugin

The Apache Struts group recommends upgrading to Apache Struts version 7.3.0 to mitigate potential security vulnerability when using the SMD / JSON-RPC support of the JSON plugin. Only Struts 7.2.1 is affected.

Please read the Security Bulletin S2-071 to find more details about this security vulnerability

All developers are strongly advised to perform this upgrade.

You can download the latest version from our download page.

14 August 2026 - CVE-2026-73633: Unbounded read of a JSON request body

The Apache Struts group recommends upgrading to Apache Struts version 7.3.0 or 6.11.0 to mitigate potential security vulnerability when populating actions from a JSON request body with the JSON plugin.

Please read the Security Bulletin S2-072 to find more details about this security vulnerability

All developers are strongly advised to perform this upgrade.

You can download the latest version from our download page.

14 August 2026 - CVE-2026-73634: Unbounded read of a Content Security Policy violation report

The Apache Struts group recommends upgrading to Apache Struts version 7.3.0 or 6.11.0 to mitigate potential security vulnerability in applications that expose an endpoint collecting Content Security Policy violation reports.

Please read the Security Bulletin S2-073 to find more details about this security vulnerability

All developers are strongly advised to perform this upgrade.

You can download the latest version from our download page.

14 August 2026 - CVE-2026-73635: Unbounded growth of localized-text caches driven by the request locale

The Apache Struts group recommends upgrading to Apache Struts version 7.3.0 or 6.11.0 to mitigate potential security vulnerability affecting localized-text lookups when no fixed locale is configured.

Please read the Security Bulletin S2-074 to find more details about this security vulnerability

All developers are strongly advised to perform this upgrade.

You can download the latest version from our download page.

1 August 2026 - Apache Struts version 7.3.0 General Availability

The Apache Struts group is pleased to announce that Apache Struts version 7.3.0 is available as a “General Availability” release. The GA designation is our highest quality grade.

The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework has been designed to streamline the full development cycle, from building, to deploying, to maintaining applications over time.

Please read the Migration Guide to find more details about how to adopt a new version.

Please read the Version Notes to find more details about performed bug fixes and improvements.

All developers are strongly advised to perform this upgrade.

The 7.x series of the Apache Struts framework has a minimum requirement of the following specification versions: Java 17 and JakartaEE.

Should any issues arise with your use of any version of the Struts framework, please post your comments to the user list, and, if appropriate, file a tracking ticket.

You can download this version from our download page.

1 August 2026 - Apache Struts version 6.11.0 General Availability

The Apache Struts group is pleased to announce that Apache Struts version 6.11.0 is available as a “General Availability” release. The GA designation is our highest quality grade.

The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework has been designed to streamline the full development cycle, from building, to deploying, to maintaining applications over time.

Please read the Version Notes to find more details about performed bug fixes and improvements.

All developers are strongly advised to perform this upgrade.

The 6.x series of the Apache Struts framework has a minimum requirement of the following specification versions: Servlet API 3.1, JSP API 2.1, and Java 8.

Should any issues arise with your use of any version of the Struts framework, please post your comments to the user list, and, if appropriate, file a tracking ticket.

You can download this version from our download page.

15 June 2026 - Apache Struts version 7.2.1 General Availability

The Apache Struts group is pleased to announce that Apache Struts version 7.2.1 is available as a “General Availability” release. The GA designation is our highest quality grade.

The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework has been designed to streamline the full development cycle, from building, to deploying, to maintaining applications over time.

Please read the Migration Guide to find more details about how to adopt a new version.

Please read the Version Notes to find more details about performed bug fixes and improvements.

All developers are strongly advised to perform this upgrade.

The 7.x series of the Apache Struts framework has a minimum requirement of the following specification versions: Java 17 and JakartaEE.

Should any issues arise with your use of any version of the Struts framework, please post your comments to the user list, and, if appropriate, file a tracking ticket.

You can download this version from our download page.

25 May 2026 - Apache Struts version 6.10.0 General Availability

The Apache Struts group is pleased to announce that Apache Struts version 6.10.0 is available as a “General Availability” release. The GA designation is our highest quality grade.

The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework has been designed to streamline the full development cycle, from building, to deploying, to maintaining applications over time.

Please read the Version Notes to find more details about performed bug fixes and improvements.

All developers are strongly advised to perform this upgrade.

The 6.x series of the Apache Struts framework has a minimum requirement of the following specification versions: Servlet API 3.1, JSP API 2.1, and Java 8.

Should any issues arise with your use of any version of the Struts framework, please post your comments to the user list, and, if appropriate, file a tracking ticket.

You can download this version from our download page.

27 April 2026 - Apache Struts version 6.9.0 General Availability

The Apache Struts group is pleased to announce that Apache Struts version 6.9.0 is available as a “General Availability” release. The GA designation is our highest quality grade.

The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework has been designed to streamline the full development cycle, from building, to deploying, to maintaining applications over time.

Please read the Version Notes to find more details about performed bug fixes and improvements.

All developers are strongly advised to perform this upgrade.

The 6.x series of the Apache Struts framework has a minimum requirement of the following specification versions: Servlet API 3.1, JSP API 2.1, and Java 8.

Should any issues arise with your use of any version of the Struts framework, please post your comments to the user list, and, if appropriate, file a tracking ticket.

You can download this version from our download page.

11 January 2026 - CVE-2025-68493: XXE vulnerability in XWork component

The Apache Struts group recommends upgrading to at least Apache Struts version 6.1.1 to mitigate potential security vulnerability.

Please read the Security Bulletin S2-069 to find more details about this security vulnerability

All developers are strongly advised to perform this upgrade.

You can download the latest version from our download page.

Skip to: Announcements - 2025

Next: Kickstart FAQ

Follow @x