Resource Exhaustion Vulnerability in Apache Struts REST Plugin by Apache
CVE-2026-104713

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
5 October 2026

What is CVE-2026-104713?

The vulnerability presents an issue within the Apache Struts REST plugin where requests can be processed without limits. An attacker may craft a request body of significant size, causing the server to allocate memory based on the size of the request. This unchecked allocation can lead to Java heap exhaustion, resulting in a denial of service for other users. Applications that do not employ the REST plugin remain unaffected. To mitigate this issue, it is recommended that users upgrade to Apache Struts versions 6.12.0 or 7.4.0, which address the vulnerability.

Affected Version(s)

Apache Struts 2.1.8 <= 2.3.37

Apache Struts 2.5.0 <= 2.5.33

Apache Struts 6.0.0 <= 6.11.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
.