24h | 7d | 30d

Overview

  • Apache Software Foundation
  • Apache Struts
  • org.apache.struts:struts2-core

05 Oct 2026
Published
05 Oct 2026
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts. Where a localized message formats a date or time argument, the formatter retained for that message by the application-wide text provider is used by concurrently served requests without isolation, so a value belonging to one user can appear in another user's response, or the rendering can fail and surface as a server error. Applications whose localized messages format no date or time arguments are not affected. This issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.

Statistics

  • 1 Post

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Struts 7.4.0 fixes four Apache Struts vulnerabilities, including OGNL injection CVE-2026-104711 and a REST plugin DoS. Upgrade now.

securityonline.info/apache-str

  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Apache Software Foundation
  • Apache Struts
  • org.apache.struts:struts2-core

05 Oct 2026
Published
05 Oct 2026
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote code execution. Struts 7 is affected only when the OGNL allowlist is disabled; it is enabled by default. Applications using the default action mapper, the restful2 mapper, or the Struts REST plugin are not affected. This issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.

Statistics

  • 1 Post

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Struts 7.4.0 fixes four Apache Struts vulnerabilities, including OGNL injection CVE-2026-104711 and a REST plugin DoS. Upgrade now.

securityonline.info/apache-str

  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Apache Software Foundation
  • Apache Struts
  • org.apache.struts:struts2-rest-plugin

05 Oct 2026
Published
05 Oct 2026
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin. A request body is read into memory without any bound on how much will be accepted, so a single request can cause the server to allocate memory in proportion to its size, exhausting the Java heap and denying service to other users. No additional setting has to be enabled. Applications that do not use the REST plugin are not affected. This issue affects Apache Struts: from 2.1.8 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.

Statistics

  • 1 Post

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Struts 7.4.0 fixes four Apache Struts vulnerabilities, including OGNL injection CVE-2026-104711 and a REST plugin DoS. Upgrade now.

securityonline.info/apache-str

  • 0
  • 0
  • 0
  • 5h ago

Overview

  • zitadel
  • zitadel

04 Oct 2026
Published
05 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.34%

KEV

Description

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, which the victim's later genuine external login then signs into.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 7 hours ago

Overview

  • zitadel
  • zitadel

04 Oct 2026
Published
05 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.2)
EPSS
0.33%

KEV

Description

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 7 hours ago

Overview

  • zitadel
  • zitadel

04 Oct 2026
Published
04 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.22%

KEV

Description

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 7 hours ago
Showing 61 to 66 of 66 CVEs