Skip to content
Rota Nacional

Cyber ·

CVE-2026-104714: race condition in Apache Struts exposes date and time values across concurrent requests

Moderate-severity advisory on a race condition in the shared message formatter of Apache Struts, published on 5 October 2026 in the oss-sec mailing list feed.

According to the text received from the oss-sec feed, published by Lukasz Lenart on 5 October 2026, the flaw is a race condition in the shared message formatter of Apache Struts. When a localized message formats a date or time argument, the formatter kept for that message can expose values across concurrent requests. The stated severity is moderate. The affected versions listed are 2.0.0 to 2.3.37, 2.5.0 to 2.5.33, 6.0.0 to 6.11.0 and 7.0.0 to 7.3.0. The source text is truncated in this copy and does not include the fixed version or mitigation plan. Those details should be checked in the original advisory and in the official Apache Struts publications. To verify, compare the Struts version in use with the affected list and confirm the fix in the official advisory.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free