CVE-2026-104713
Received Received - Intake

Unbounded Memory Allocation in Apache Struts REST Plugin

Vulnerability report for CVE-2026-104713, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Apache Software Foundation

Description

Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin. A request body is read into memory without any bound on how much will be accepted, so a single request can cause the server to allocate memory in proportion to its size, exhausting the Java heap and denying service to other users. No additional setting has to be enabled. Applications that do not use the REST plugin are not affected. This issue affects Apache Struts: from 2.1.8 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
Apache Software Foundation Apache Struts 2.1.8
Apache Software Foundation Apache Struts 2.5.0
Apache Software Foundation Apache Struts 6.0.0
Apache Software Foundation Apache Struts 7.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an allocation of resources without limits or throttling in the Apache Struts REST plugin. A request body is read into memory without any bound on how much will be accepted, so a single large request can exhaust the Java heap memory, causing a denial of service to other users. No additional settings need to be enabled for this issue to occur.

Detection Guidance

To detect this vulnerability, check if your Apache Struts application uses the REST plugin and is running a vulnerable version. Inspect server logs for unusually large request bodies or memory exhaustion errors. Use commands like 'curl -v -X POST -d @large_file.txt http://target-url' to test for unbounded memory allocation. Monitor Java heap usage with tools like jstat or VisualVM.

Impact Analysis

This vulnerability can cause your Apache Struts server to run out of memory due to a single oversized request, leading to system crashes or unresponsiveness. This disrupts service availability for all users relying on the affected application.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling denial-of-service attacks that disrupt service availability. GDPR requires maintaining system availability, and HIPAA mandates safeguards against service disruptions. Exploiting this flaw may lead to unauthorized resource exhaustion, potentially violating availability requirements in these standards.

Mitigation Strategies

Immediately upgrade Apache Struts to version 6.12.0 or 7.4.0, which fixes the issue by enforcing a 2 MB request body limit. As a temporary measure, configure your reverse proxy or servlet container to enforce request size limits. Disable the REST plugin if not in use.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104713. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart