
🚨 SECURITY UPDATE: Apache Struts 7.4.0 and 6.12.0 fix four vulnerabilities (S2-075 to S2-078). ➡️ CVE-2026-104713 (Important): the REST plugin reads request bodies without a size limit, allowing heap exhaustion and denial of service. 7.4.0 adds a 2 MB default limit. ➡️ CVE-2026-104711 (Moderate): OGNL injection through the legacy RESTful action mapper, which can lead to remote code execution. On 7.x, only deployments with the OGNL allowlist disabled are affected. ➡️ CVE-2026-104712 / CVE-2026-104714 (Moderate): a BigDecimal rendering DoS and a shared date formatter race that can cause information disclosure or DoS. ⚠️ No official CVSS yet. Not in CISA KEV, and no exploitation reported. 🔴 Upgrade to Struts 7.4.0 or 6.12.0. The 2.x branches are end-of-life: plan a migration. Full breakdown 👉 https://www.threatwire.tech/news/apache-struts-7-4-0-fixes-four-security-flaws #CyberSecurity #InfoSec #ApacheStruts #Java
