Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104714— Apache Struts: Shared message formatter exposes date and time values across concurrent requests

Quick assessment

Affected
Apache Software Foundation Apache Struts
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Struts 中存在并发执行时使用共享资源且同步不当(竞态条件)漏洞。当本地化消息格式化日期或时间参数时,应用程序范围内文本提供程序为该消息保留的格式化器会被并发处理的请求共享,缺乏隔离性,导致一个用户的值可能出现在另一个用户的响应中,或者渲染失败并表现为服务器错误。未本地化消息格式化日期或时间参数的应用不受此漏洞影响。 此漏洞影响以下 Apache Struts 版本: 2.0.0 至 2.3.37 2.5.0 至 2.5.33 6.0.0 至 6.11.0 7.0.0 至 7.3.0 建议用户升级

AI Predicted 5.3 Difficulty: Easy

Affected Version Matrix 4

VendorProduct Version RangeStatus
Apache Software Foundation Apache Struts 2.0.0≤ 2.3.37 affected
2.5.0≤ 2.5.33 affected
6.0.0≤ 6.11.0 affected
7.0.0≤ 7.3.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104714

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Struts: Shared message formatter exposes date and time values across concurrent requests
Source: CVE Program / CVE List V5
Vulnerability Description
Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts. Where a localized message formats a date or time argument, the formatter retained for that message by the application-wide text provider is used by concurrently served requests without isolation, so a value belonging to one user can appear in another user's response, or the rendering can fail and surface as a server error. Applications whose localized messages format no date or time arguments are not affected. This issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
使用共享资源的并发执行不恰当同步问题(竞争条件)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Struts 2.0.0 ~ 2.3.37 -

II. Public POCs for CVE-2026-104714

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104714

请登录查看更多情报信息。

Other References for CVE-2026-104714 (1)

Same Patch Batch · Apache Software Foundation · 2026-10-05 · 4 CVEs total

CVE-2026-104713 Apache Struts: Unbounded request body read in the REST plugin
CVE-2026-104712 Apache Struts: Disproportionate response size when rendering BigDecimal request parameters
CVE-2026-104711 Apache Struts: OGNL injection in the legacy RESTful action mapper

IV. Related Vulnerabilities

V. Comments for CVE-2026-104714

No comments yet


Leave a comment