CVE-2026-104713: Apache Struts: Unbounded request body read in the REST plugin

Published Oct 5, 2026
·
Updated

Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin. A request body is read into memory without any bound on how much will be accepted, so a single request can cause the server to allocate memory in proportion to its size, exhausting the Java heap and denying service to other users. No additional setting has to be enabled. Applications that do not use the REST plugin are not affected.

This issue affects Apache Struts: from 2.1.8 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0.

Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.

Affected Software

1 affected component
Apache Struts>=2.1.8<=2.3.37, >=2.5.0<=2.5.33, >=6.0.0<=6.11.0, >=7.0.0<=7.3.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache Struts REST plugin to a version that resolves this vulnerability.

    Fixed in 6.12.0
  2. Upgrade

    Upgrade Apache Struts REST plugin to a version that resolves this vulnerability.

    Fixed in 7.4.0

Event History

Oct 5, 2026
CVE Published
via MITRE·06:36 PM
Data Sourced
via MITRE·06:36 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Applications using the Apache Struts REST plugin are affected if they run versions 2.1.8 through 2.3.37, 2.5.0 through 2.5.33, 6.0.0 through 6.11.0, or 7.0.0 through 7.3.0. Applications that do not use the REST plugin are not affected.

2

What does an attacker need to do to cause denial of service?

An attacker can send a single request with a sufficiently large request body. The REST plugin reads the body into memory without an acceptance bound, allowing heap exhaustion; no additional setting needs to be enabled.

3

What is the recommended remediation?

Upgrade to Apache Struts 6.12.0 or 7.4.0, which fix the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203