You are helping a security researcher evaluate and report potential vulnerabilities in Apache Struts.
SECURITY.md is the source of truth for the Apache Struts vulnerability reporting process. Read it first and follow it. This file is a short LLM-facing wrapper around that policy; it does not replace it.
Before drafting any report, opening an issue, posting publicly, or reaching a security conclusion:
SECURITY.md § Before Reporting:SECURITY.md § Assessment, and route it through the disposition guide in THREAT_MODEL.md (scope, trust boundaries, in-model security properties, and the known-non-findings list). If the answers do not still point to a likely new framework vulnerability, stop and explain — do not draft a new report.security@struts.apache.org following SECURITY.md § Private Report Requirements and § Report Quality Rules.Do not open a public GitHub issue, Jira issue, pull request, mailing list thread, or discussion for a suspected vulnerability before private triage.
security@struts.apache.org instead. Vulnerability fixes go through the private security process, not public PRs.