« Back to list

Apache

Apache Struts: vulnerabilities and CVEs

Apache Struts has 96 published vulnerabilities, 9 of them in the last 12 months. 17 are rated critical and 8 are listed by CISA as actively exploited.

CVEs96
Last 12 months9
Critical17
Actively exploited8

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2013-2251Critical (9.8)100%⚠ Active exploitationJul 20, 2013
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
CVE-2017-9791Critical (9.8)99%⚠ Active exploitationJul 10, 2017
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
CVE-2006-1547High (7.5)55%⚠ Active exploitationMar 30, 2006
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the…
CVE-2012-0391Critical (9.8)76%⚠ Active exploitationJan 8, 2012
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers…
CVE-2017-9805High (8.1)99%⚠ Active exploitationSep 15, 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code…
CVE-2020-17530Critical (9.8)96%⚠ Active exploitationDec 11, 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
CVE-2017-5638Critical (9.8)100%⚠ Active exploitationMar 11, 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to…
CVE-2018-11776High (8.1)100%⚠ Active exploitationAug 22, 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-73635High (7.5)0.70%—Aug 15, 2026
Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an…
CVE-2026-73634High (7.5)0.73%—Aug 15, 2026
Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how…
CVE-2026-73632Medium (4.3)0.38%—Aug 15, 2026
Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one…
CVE-2026-73631Medium (4.3)0.38%—Aug 15, 2026
Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one request to become…
CVE-2026-73633High (7.5)0.70%—Aug 14, 2026
Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without…
CVE-2025-68493High (8.1)46%—Jan 11, 2026
Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version…
CVE-2025-66675High (8.2)0.59%—Dec 10, 2025
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3. Users are…
CVE-2025-64775High (7.5)1.5%—Dec 1, 2025
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.0 through 7.0.3. Users are…
CVE-2025-46581Critical (9.8)0.80%—Oct 14, 2025
ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges.
CVE-2024-53677Critical (9.5)70%—Dec 11, 2024
File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform…
CVE-2023-50164Critical (9.8)81%—Dec 7, 2023
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended…
CVE-2023-41835High (7.5)7.3%—Dec 5, 2023
When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in struts.multipart.saveDir even if the request has been denied. Users are recommended to…
CVE-2023-34396High (7.5)5.5%—Jun 14, 2023
Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2. Upgrade to Struts 2.5.31 or 6.1.2.1 or…
CVE-2023-34149Medium (6.5)5.4%—Jun 14, 2023
Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2. Upgrade to Struts 2.5.31 or 6.1.2.1 or…
CVE-2021-31805Critical (9.8)85%—Apr 12, 2022
The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the…
CVE-2020-26259Medium (6.8)82%—Dec 16, 2020
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling. The vulnerability may allow a…
CVE-2020-26258High (7.7)82%—Dec 16, 2020
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a…
CVE-2020-17530Critical (9.8)96%⚠ Active exploitationDec 11, 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
CVE-2019-0233High (7.5)68%—Sep 14, 2020
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
CVE-2019-0230Critical (9.8)97%—Sep 14, 2020
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
CVE-2015-2992Medium (6.1)5.8%—Feb 27, 2020
Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
CVE-2012-1592High (8.8)29%—Dec 5, 2019
A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.
CVE-2011-3923Critical (9.8)89%—Nov 1, 2019
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.
CVE-2018-11776High (8.1)100%⚠ Active exploitationAug 22, 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used…
CVE-2018-1327High (7.5)8.6%—Mar 27, 2018
The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with specially crafted XML payload. Upgrade to the Apache Struts version 2.5.16…
CVE-2017-15707Medium (6.2)4.9%—Dec 1, 2017
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
CVE-2016-3090High (8.8)5.7%—Oct 30, 2017
The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL expression with ANTLR tooling.
CVE-2016-4461High (8.8)8.1%—Oct 16, 2017
Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. NOTE: this vulnerability exists because of an incomplete fix…
CVE-2015-5169Medium (6.1)7.5%—Sep 25, 2017
Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.
CVE-2017-9804High (7.5)8.2%—Sep 20, 2017
In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application5
  2. T1059.007 JavaScript3
  3. T1059 Command and Scripting Interpreter1
  4. T1059.001 PowerShell1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Apache