🔒 Apache Struts security bulletins S2-070 to S2-074 are published. They affect the JSON plugin, CSP violation reporting and localized-text caching.
Upgrade to 7.3.0 or 6.11.0!
struts.apache.org/announce-2026
Apache Struts is a free open-source framework for creating Java web applications.
- Apache Struts 7.3.0 & 6.11.0 are officially released! Have fun! lists.apache.org/thread/5wqokq1… lists.apache.org/thread/p281hjj… #apache #struts #release
- The Apache Struts 6.11.0 vote is open! A maintenance release for the 6.x line: one bug fix, two improvements and two dependency bumps. Everyone who tests the build is invited to vote! lists.apache.org/thread/tlwg519… #apache #struts #vote
- The Apache Struts 7.3.0 release vote is open! 7 breaking changes, plus a broad set of improvements and bug fixes. Everyone who tests the build is invited to vote! lists.apache.org/thread/k217jsl… #apache #struts #vote
- And here you have a full blown test build of incoming Struts 7.3.0! It contains a lot of new stuff plus support for WebJars, which will be used in other plugins! lists.apache.org/thread/4vfx244… #struts #test #build

