FAIL › dossier
Struts 1
PRODUCT· dossier confidence 20%
Apache Struts is a widely used Java web application framework with a documented history of critical remote code execution vulnerabilities, highlighting significant security risks and potential compliance concerns for organizations utilizing it. These vulnerabilities underscore the need for rigorous vulnerability management and secure coding practices.
PROFILE
CategoryWeb Application FrameworkWhat they doApache Struts is a widely used Java web application framework for building enterprise web applications.
Websitehttps://struts.apache.org ↗
SECURITY POSTURE
Apache Struts has a documented history of critical remote code execution vulnerabilities, highlighting significant security risks and potential compliance concerns for organizations utilizing it. The framework's open-source nature and widespread adoption necessitate careful monitoring and patching to mitigate potential exploits.
Notable failures
- CVE-2017-9791 RCE via improper input validation
- CVE-2006-1547 ActionForm DoS vulnerability
Patterns: repeated unpatched edge-device RCEs; improper input validation leading to RCE
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-02-10 | CVE-2017-9791 | high | Apache Struts 1 suffered an improper input validation flaw allowing remote code execution via malicious field values in raw messages. |
| 2022-01-21 | CVE-2006-1547 | high | Apache Struts 1 ActionForm DoS vulnerability exploited in the wild before patching. |
DOSSIER SOURCES
- Software Version Tracker & EOL Calendar - Track Releases & Support Status · versionlog.com
- Apache Release Notes - August 2026 Latest Updates - Releasebot · releasebot.io
- HTTP Server: Releases, patches & end-of-life - versio.io · www.versio.io
Open questions: What is the current patching status of Apache Struts 1? · Are there any ongoing security advisories for Apache Struts 1?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-27 04:07:51.556942+00:00