CVE-2026-104713: Apache Struts: Unbounded request body read in the REST plugin
Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin. A request body is read into memory without any bound on how much will be accepted, so a single request can cause the server to allocate memory in proportion to its size, exhausting the Java heap and denying service to other users. No additional setting has to be enabled. Applications that do not use the REST plugin are not affected.
This issue affects Apache Struts: from 2.1.8 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0.
Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Struts REST pluginto a version that resolves this vulnerability.Fixed in 6.12.0 - Upgrade
Upgrade
Apache Struts REST pluginto a version that resolves this vulnerability.Fixed in 7.4.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Applications using the Apache Struts REST plugin are affected if they run versions 2.1.8 through 2.3.37, 2.5.0 through 2.5.33, 6.0.0 through 6.11.0, or 7.0.0 through 7.3.0. Applications that do not use the REST plugin are not affected.
What does an attacker need to do to cause denial of service?
An attacker can send a single request with a sufficiently large request body. The REST plugin reads the body into memory without an acceptance bound, allowing heap exhaustion; no additional setting needs to be enabled.
What is the recommended remediation?
Upgrade to Apache Struts 6.12.0 or 7.4.0, which fix the issue.