Fork me on GitHub
Edit on GitHub

Announcements 2026

Skip to: Announcements - 2025

14 August 2026 - CVE-2026-73631: Shared parsing state in the JSON plugin

The Apache Struts group recommends upgrading to Apache Struts version 7.3.0 to mitigate potential security vulnerability when populating actions from a JSON request body with the JSON plugin. Only Struts 7.2.1 is affected.

Please read the Security Bulletin S2-070 to find more details about this security vulnerability

All developers are strongly advised to perform this upgrade.

You can download the latest version from our download page.

14 August 2026 - CVE-2026-73632: Shared serialization state in the JSON plugin

The Apache Struts group recommends upgrading to Apache Struts version 7.3.0 to mitigate potential security vulnerability when using the SMD / JSON-RPC support of the JSON plugin. Only Struts 7.2.1 is affected.

Please read the Security Bulletin S2-071 to find more details about this security vulnerability

All developers are strongly advised to perform this upgrade.

You can download the latest version from our download page.

14 August 2026 - CVE-2026-73633: Unbounded read of a JSON request body

The Apache Struts group recommends upgrading to Apache Struts version 7.3.0 or 6.11.0 to mitigate potential security vulnerability when populating actions from a JSON request body with the JSON plugin.

Please read the Security Bulletin S2-072 to find more details about this security vulnerability

All developers are strongly advised to perform this upgrade.

You can download the latest version from our download page.

14 August 2026 - CVE-2026-73634: Unbounded read of a Content Security Policy violation report

The Apache Struts group recommends upgrading to Apache Struts version 7.3.0 or 6.11.0 to mitigate potential security vulnerability in applications that expose an endpoint collecting Content Security Policy violation reports.

Please read the Security Bulletin S2-073 to find more details about this security vulnerability

All developers are strongly advised to perform this upgrade.

You can download the latest version from our download page.

14 August 2026 - CVE-2026-73635: Unbounded growth of localized-text caches driven by the request locale

The Apache Struts group recommends upgrading to Apache Struts version 7.3.0 or 6.11.0 to mitigate potential security vulnerability affecting localized-text lookups when no fixed locale is configured.

Please read the Security Bulletin S2-074 to find more details about this security vulnerability

All developers are strongly advised to perform this upgrade.

You can download the latest version from our download page.

1 August 2026 - Apache Struts version 7.3.0 General Availability

The Apache Struts group is pleased to announce that Apache Struts version 7.3.0 is available as a “General Availability” release. The GA designation is our highest quality grade.

The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework has been designed to streamline the full development cycle, from building, to deploying, to maintaining applications over time.

Please read the Migration Guide to find more details about how to adopt a new version.

Please read the Version Notes to find more details about performed bug fixes and improvements.

All developers are strongly advised to perform this upgrade.

The 7.x series of the Apache Struts framework has a minimum requirement of the following specification versions: Java 17 and JakartaEE.

Should any issues arise with your use of any version of the Struts framework, please post your comments to the user list, and, if appropriate, file a tracking ticket.

You can download this version from our download page.

1 August 2026 - Apache Struts version 6.11.0 General Availability

The Apache Struts group is pleased to announce that Apache Struts version 6.11.0 is available as a “General Availability” release. The GA designation is our highest quality grade.

The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework has been designed to streamline the full development cycle, from building, to deploying, to maintaining applications over time.

Please read the Version Notes to find more details about performed bug fixes and improvements.

All developers are strongly advised to perform this upgrade.

The 6.x series of the Apache Struts framework has a minimum requirement of the following specification versions: Servlet API 3.1, JSP API 2.1, and Java 8.

Should any issues arise with your use of any version of the Struts framework, please post your comments to the user list, and, if appropriate, file a tracking ticket.

You can download this version from our download page.

15 June 2026 - Apache Struts version 7.2.1 General Availability

The Apache Struts group is pleased to announce that Apache Struts version 7.2.1 is available as a “General Availability” release. The GA designation is our highest quality grade.

The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework has been designed to streamline the full development cycle, from building, to deploying, to maintaining applications over time.

Please read the Migration Guide to find more details about how to adopt a new version.

Please read the Version Notes to find more details about performed bug fixes and improvements.

All developers are strongly advised to perform this upgrade.

The 7.x series of the Apache Struts framework has a minimum requirement of the following specification versions: Java 17 and JakartaEE.

Should any issues arise with your use of any version of the Struts framework, please post your comments to the user list, and, if appropriate, file a tracking ticket.

You can download this version from our download page.

25 May 2026 - Apache Struts version 6.10.0 General Availability

The Apache Struts group is pleased to announce that Apache Struts version 6.10.0 is available as a “General Availability” release. The GA designation is our highest quality grade.

The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework has been designed to streamline the full development cycle, from building, to deploying, to maintaining applications over time.

Please read the Version Notes to find more details about performed bug fixes and improvements.

All developers are strongly advised to perform this upgrade.

The 6.x series of the Apache Struts framework has a minimum requirement of the following specification versions: Servlet API 3.1, JSP API 2.1, and Java 8.

Should any issues arise with your use of any version of the Struts framework, please post your comments to the user list, and, if appropriate, file a tracking ticket.

You can download this version from our download page.

27 April 2026 - Apache Struts version 6.9.0 General Availability

The Apache Struts group is pleased to announce that Apache Struts version 6.9.0 is available as a “General Availability” release. The GA designation is our highest quality grade.

The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework has been designed to streamline the full development cycle, from building, to deploying, to maintaining applications over time.

Please read the Version Notes to find more details about performed bug fixes and improvements.

All developers are strongly advised to perform this upgrade.

The 6.x series of the Apache Struts framework has a minimum requirement of the following specification versions: Servlet API 3.1, JSP API 2.1, and Java 8.

Should any issues arise with your use of any version of the Struts framework, please post your comments to the user list, and, if appropriate, file a tracking ticket.

You can download this version from our download page.

11 January 2026 - CVE-2025-68493: XXE vulnerability in XWork component

The Apache Struts group recommends upgrading to at least Apache Struts version 6.1.1 to mitigate potential security vulnerability.

Please read the Security Bulletin S2-069 to find more details about this security vulnerability

All developers are strongly advised to perform this upgrade.

You can download the latest version from our download page.

Skip to: Announcements - 2025

Next: Kickstart FAQ

Follow @x