CVE-2026-104714

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts. Where a localized message formats a date or time argument, the formatter retained for that message by the application-wide text provider is used by concurrently served requests without isolation, so a value belonging to one user can appear in another user's response, or the rendering can fail and surface as a server error. Applications whose localized messages format no date or time arguments are not affected. This issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-05: 110-05
Referenced assets1 URL
By indicator
Full discourse1 post
  • ThreatWire@ThreatWire_

    🚨 SECURITY UPDATE: Apache Struts 7.4.0 and 6.12.0 fix four vulnerabilities (S2-075 to S2-078). ➡️ CVE-2026-104713 (Important): the REST plugin reads request bodies without a size limit, allowing heap exhaustion and denial of service. 7.4.0 adds a 2 MB default limit. ➡️ CVE-2026-104711 (Moderate): OGNL injection through the legacy RESTful action mapper, which can lead to remote code execution. On 7.x, only deployments with the OGNL allowlist disabled are affected. ➡️ CVE-2026-104712 / CVE-2026-104714 (Moderate): a BigDecimal rendering DoS and a shared date formatter race that can cause information disclosure or DoS. ⚠️ No official CVSS yet. Not in CISA KEV, and no exploitation reported. 🔴 Upgrade to Struts 7.4.0 or 6.12.0. The 2.x branches are end-of-life: plan a migration. Full breakdown 👉 https://www.threatwire.tech/news/apache-struts-7-4-0-fixes-four-security-flaws #CyberSecurity #InfoSec #ApacheStruts #Java

    01091601
    1.7K followersView on X

Explore more