Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
Loading...
Loading...
Score elevated to 9.0 because EPSS predicts 94% probability of exploitation within the next 30 days (top 0.1% of all CVEs). NVD baseline CVSS 8.1 retained for reference. Confidence: see factors.
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
April 26, 2016
May 6, 2026
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.apache.struts:struts2-core | 2.3.28 | 2.3.28.1 | — |
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2016-3081
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.