Skip to main content
Vulnerability Database/CVE-2026-104714

CVE-2026-104714: Apache Struts Race Condition Vulnerability

CVE-2026-104714 is a race condition vulnerability in Apache Struts affecting date and time formatting in localized messages. This flaw can expose user data across concurrent requests or cause server errors. This article covers technical details, affected versions, impact, and mitigation steps.

Published:

CVE-2026-104714 Overview

CVE-2026-104714 is a race condition in Apache Struts affecting how localized messages format date and time arguments. The application-wide text provider retains a shared formatter that concurrent requests use without isolation. One user's data can leak into another user's response, or rendering can fail with a server error.

The flaw is tracked under CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization and is documented in the Apache Struts Security Advisory S2-078. Applications whose localized messages do not format date or time arguments are not affected.

Critical Impact

Data belonging to one authenticated user can appear in another user's HTTP response, breaking tenant and session isolation in Struts-based web applications.

Affected Products

  • Apache Struts 2.0.0 through 2.3.37
  • Apache Struts 2.5.0 through 2.5.33
  • Apache Struts 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0

Discovery Timeline

  • 2026-10-05 - CVE-2026-104714 published to the National Vulnerability Database (NVD)
  • 2026-10-05 - Apache Struts Security Advisory S2-078 released and disclosed on the OSS-Security mailing list
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-104714

Vulnerability Analysis

Apache Struts renders user-facing text through a localized message system. When a message template includes a date or time argument, the framework instantiates a java.text.Format subclass such as DateFormat or MessageFormat to render that argument.

The application-wide text provider caches that formatter and reuses it across requests. java.text.Format and its subclasses are not thread-safe. Concurrent requests calling format() on the same instance race on the formatter's internal state.

The outcome is nondeterministic. In one race, Request A's date value is written into Request B's output. In another race, internal state corruption triggers an exception that surfaces as an HTTP 500 server error.

The exploit path requires only that an attacker send concurrent authenticated requests to any action that renders a localized message with a date or time argument. No specially crafted payload is needed, which lowers the barrier to triggering cross-request data exposure.

Root Cause

The root cause is improper synchronization around a shared mutable formatter object held by the text provider. The framework assumed the formatter could be safely cached per message key, but DateFormat instances maintain mutable Calendar and parsing state between calls to format().

Attack Vector

The attack is network-reachable and requires low privileges because any authenticated session that reaches a vulnerable action can participate in the race. An attacker generates parallel request streams to force contention on the shared formatter. Successful races leak another session's rendered date values or trigger denial-of-service through repeated server errors.

See the Apache Struts S2-078 advisory for the full technical description.

Detection Methods for CVE-2026-104714

Indicators of Compromise

  • Unexpected java.lang.ArrayIndexOutOfBoundsException, NumberFormatException, or ConcurrentModificationException stack traces originating in java.text.DateFormat or java.text.MessageFormat within Struts request logs.
  • User reports of date or time values in rendered pages that do not match the authenticated user's own data.
  • Elevated HTTP 500 response rates on action endpoints that render localized messages during periods of high concurrency.

Detection Strategies

  • Inventory running Apache Struts versions across application servers and flag any instance in the ranges 2.0.0-2.3.37, 2.5.0-2.5.33, 6.0.0-6.11.0, or 7.0.0-7.3.0.
  • Review resource bundles and .properties files for message keys containing {0,date}, {0,time}, or {0,date,...} patterns to identify affected rendering paths.
  • Correlate web server access logs with application exception logs to find bursts of formatter-related exceptions tied to concurrent sessions.

Monitoring Recommendations

  • Alert on new occurrences of java.text.* exceptions in application logs after deployment.
  • Monitor HTTP 500 rates per endpoint and investigate spikes on pages that render localized dates.
  • Track outbound response bodies for anomalies in rendered date fields during load testing to confirm patch effectiveness.

How to Mitigate CVE-2026-104714

Immediate Actions Required

  • Upgrade Apache Struts to version 6.12.0 for the 6.x branch or 7.4.0 for the 7.x branch, which contain the fix.
  • Identify applications still on end-of-life Struts 2.3.x and 2.5.x branches and plan migration, as these branches did not receive a backport in the advisory.
  • Audit all resource bundles for date and time format arguments and prioritize patching services that expose them to authenticated users.

Patch Information

The Apache Struts project fixed the race condition in versions 6.12.0 and 7.4.0 by ensuring per-request formatter isolation rather than sharing a cached formatter across concurrent threads. Refer to the Apache Struts S2-078 advisory and the OSS-Security disclosure for upgrade guidance.

Workarounds

  • Remove date and time arguments from localized messages where feasible, since messages without such arguments are not affected.
  • Pre-format date and time values in the action class and pass them to templates as plain strings, bypassing the shared formatter path.
  • Restrict access to affected endpoints behind authentication and rate limiting to reduce the window for race exploitation until the upgrade is applied.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.