Apache Struts

12 known vulnerabilities in Apache Struts, 3 critical, 5 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2020-17530 CVSS 9.8 critical · actively exploited Apache Struts Remote Code Execution Vulnerability
  • CVE-2018-11776 CVSS 8.1 high · actively exploited Apache Struts Remote Code Execution Vulnerability
  • CVE-2017-9805 CVSS 8.1 high · actively exploited Apache Struts Deserialization of Untrusted Data Vulnerability
  • CVE-2017-9791 CVSS 9.8 critical · actively exploited Apache Struts 1 Improper Input Validation Vulnerability
  • CVE-2017-5638 CVSS 9.8 critical · actively exploited Apache Struts Remote Code Execution Vulnerability

Latest vulnerabilities

  • CVE-2026-104714 not yet scored Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts. Where a…
  • CVE-2026-104713 not yet scored Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin. A request body is read into memory…
  • CVE-2026-104712 not yet scored Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an…
  • CVE-2026-104711 not yet scored Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in…
  • CVE-2026-73635 CVSS 7.5 high Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used…
  • CVE-2026-73634 CVSS 7.5 high Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security…
  • CVE-2026-73633 CVSS 7.5 high Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions…
  • CVE-2020-17530 CVSS 9.8 critical · actively exploited Apache Struts Remote Code Execution Vulnerability
  • CVE-2018-11776 CVSS 8.1 high · actively exploited Apache Struts Remote Code Execution Vulnerability
  • CVE-2017-9805 CVSS 8.1 high · actively exploited Apache Struts Deserialization of Untrusted Data Vulnerability
  • CVE-2017-9791 CVSS 9.8 critical · actively exploited Apache Struts 1 Improper Input Validation Vulnerability
  • CVE-2017-5638 CVSS 9.8 critical · actively exploited Apache Struts Remote Code Execution Vulnerability