Visit NES for Apache Struts Home Page
Apache Struts Forward Compatibility 1.3 Release Notes
5 versions
Apache Struts 1.3 Forward Compatibility runs on Jakarta EE 9 compatible servers, providing a modernized framework for legacy Struts 1 applications.
Dec 10, 2025
Latest: 1.4.4
3 Patched CVEs
December 2025
September 2025
August 2025
1.4.2
Released on Aug 25, 2025 Full Version:
1.3.10-struts-1.4.2
Notes
- updates to
struts-facesto fully support Jakarta EE 9
1.4.1
Released on Aug 4, 2025 Full Version:
1.3.10-struts-1.4.1
Bug Fixes
This release patches the following:
- CVE-2025-54656: Improper Output Neutralization for Logs Vulnerability
- CVE-2025-48976: FileUpload DoS via part headers
- CVE-2025-48734: Improper Access Control vulnerability
- Dependency upgrade of beanutils to
1.11.0or override tones-v1.7.4addresses this vulnerability.
- Dependency upgrade of beanutils to
Dependency Upgrades
- commons-beanutils:commons-beanutils 1.9.4 -> 1.11.0
- org.apache.commons:commons-fileupload2-core 2.0.0-M1 -> 2.0.0-M4
- org.apache.commons:commons-fileupload2-jakarta 2.0.0-M1 -> commons-fileupload2-jakarta-servlet5 2.0.0-M4
June 2025
1.4.0
Released on Jun 25, 2025 Full Version:
1.3.10-struts-1.4.0
Notes
- This release originates from NES for Apache Struts 1.3.x and is designed to be compatible with Jakarta EE environments.
Dependency Upgrades
- commons-fileupload 2.0.0-M1
- Jakarta EE 9 compatibility:
- jakarta.faces-api 3.0.0
- jakarta.servlet-api 5.0.0
- jakarta.servlet.jsp-api 3.0.0
- jakarta.el-api 4.0.0
Stay in the loop
~/herodevs-spring-framework-support
herodevs@nes:open-source$ ./display-support-info.sh