org.apache.struts:struts2-core vulnerabilities
CVEs whose affected-version data names the org.apache.struts:struts2-core package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-104714NoneConcurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts
Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts. Where a localized message formats a date or time argument, the formatter retained for that message by the applica…
CVE-2026-104712NoneAsymmetric resource consumption (amplification) vulnerability in Apache Struts
Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the…
CVE-2026-104711NoneImproper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts
Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted re…