Bug 38374 - Validation always skipped with Globals.CANCEL_KEY. Bug 38534 - DOS attack, application hack. Bug 38749 - XSS vulnerability in LookupDispatchAction.
1.2.9 is available for download @ http://struts.apache.org/download.cgi
Java please advise and provide an updated ebuild as necessary.
karltk did the 1.2.9 bump earlier today.
Struts appears to never have been stable -> closing with NO GLSA.