CVE-2026-104713
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Apache Struts is a popular open-source web application framework for developing Java EE web applications. The optional REST plugin maps HTTP requests to actions and uses content-type handlers to populate those actions from JSON, XML, or other request bodies.
A denial of service vulnerability (CVE-2026-104713) has been identified in the Apache Struts REST plugin, which allows attackers to exhaust the Java heap by sending a request with a very large body. A single request can make the server allocate memory in proportion to the size of the body, denying service to other users.
Per OWASP: The Denial of Service (DoS) attack is focused on making a resource (site, application, server) unavailable for the purpose it was designed.
This issue affects multiple versions of Apache Struts.
Details
Module Info
- Product: Apache Struts
- Affected packages: org.apache.struts:struts2-rest-plugin
- Affected versions: >=2.1.8 <=2.3.37, >=2.5.0 <=2.5.33, >=6.0.0 <=6.11.0, >=7.0.0 <=7.3.0
- GitHub repository: https://github.com/apache/struts
- Published packages: https://central.sonatype.com/artifact/org.apache.struts/struts2-rest-plugin
- Package manager: Maven
- Fixed in:
- OSS Apache Struts 6.12.0, 7.4.0
- NES for Apache Struts nes-v2.5.41
Vulnerability Info
This Medium-severity vulnerability is found in the org.apache.struts:struts2-rest-plugin package in multiple versions of Apache Struts. When a request reaches an action through the REST plugin, ContentTypeInterceptor selects a content-type handler for the request and passes it a reader over the raw request body:
if (request.getContentLength() > 0) {
InputStream is = request.getInputStream();
InputStreamReader reader = new InputStreamReader(is);
handler.toObject(invocation, reader, target);
}
return invocation.invoke();The only check is that the request declares a positive Content-Length; nothing limits how many characters the handler may read from the reader. The handler deserializes the whole body into memory before the action is invoked, so a client can send an arbitrarily large body and force the server to allocate memory in proportion to it until the heap is exhausted. No additional setting has to be enabled: any application that uses the REST plugin to accept request bodies is exposed in its default configuration. Applications that do not use the REST plugin are not affected.
Mitigation
Only recent versions of Apache Struts are community-supported. Older lines are End-of-Life and will not receive any updates to address this issue.
Users of the affected components should apply one of the following mitigations:
- Upgrade affected applications to a supported version of Apache Struts.
- Leverage a commercial support partner like HeroDevs for post-EOL security support.
Credits
- n0mi1k (finder)