Welcome to the Apache Struts project Menu Toggle navigation Home Welcome Download Releases Announcements License Thanks! Sponsorship Privacy Policy Support User Mailing List Issue Tracker Reporting Security Issues Commercial Support End-of-Life Versions Version Notes Security Bulletins IntelliJ IDEA plugin Maven Project Info Struts Core Dependencies Plugin Dependencies Documentation Birds Eye Key Technologies Kickstart FAQ Wiki Getting Started Security Guide Core Developers Guide Tag Developers Guide Maven Archetypes Plugins Struts Core API Tag reference FAQs Plugin registry Contributing You at Struts How to Help FAQ Development Lists Submitting patches Source Code and Builds Coding standards Contributors Guide Release Guidelines PMC Charter Volunteers Source Repository Updating the website Apache Struts Apache Struts is a free, open-source, MVC framework for creating elegant, modern Java web applications. It favors convention over configuration, is extensible using a plugin architecture, and ships with plugins to support REST, AJAX and JSON. Download Technology Primer Apache Struts 7.2.1 GA Apache Struts 7.2.1 GA has been released on 15 June 2026. Read more in Announcement or in Version notes Apache Struts 6.10.0 GA Apache Struts 6.10.0 GA has been released on 25 May 2026. Read more in Announcement or in Version notes End-of-Life Struts Versions Some Struts versions are no longer supported and receive no further security patches. We recommend migrating to the latest release. If migration is not immediately feasible, see End-of-Life versions for available options. CVE-2025-68493: XXE vulnerability in XWork component Upgrade to at least Apache Struts 6.1.1 to mitigate the vulnerability. Read more in the Announcement or in the Security Bulletin S2-069 Google's Patch Reward program During SFHTML5 Google announced that they extend their program to cover the Apache Struts project as well. Now you can earn money preparing patches for us! read more CVE-2025-64775 File leak in multipart request processing causes disk exhaustion (DoS) Upgrade to Apache Struts 6.8.0 or 7.1.1 to mitigate the vulnerability. Read more in the Announcement or in the Security Bulletin S2-068 Keep in touch: Star Follow @TheApacheStruts Copyright © 2000-2025 The Apache Software Foundation. Apache Struts, Struts, Apache, the Apache feather logo, and the Apache Struts project logos are trademarks of The Apache Software Foundation. All Rights Reserved. Logo and website design donated by SoftwareMill. Follow @x