CVE-2026-104713

Denial of Service
Affects
Apache Struts
in
Apache Struts
No items found.
Versions
>=2.1.8 <=2.3.37, >=2.5.0 <=2.5.33, >=6.0.0 <=6.11.0, >=7.0.0 <=7.3.0

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Apache Struts is a popular open-source web application framework for developing Java EE web applications. The optional REST plugin maps HTTP requests to actions and uses content-type handlers to populate those actions from JSON, XML, or other request bodies.

A denial of service vulnerability (CVE-2026-104713) has been identified in the Apache Struts REST plugin, which allows attackers to exhaust the Java heap by sending a request with a very large body. A single request can make the server allocate memory in proportion to the size of the body, denying service to other users.

Per OWASP: The Denial of Service (DoS) attack is focused on making a resource (site, application, server) unavailable for the purpose it was designed.

This issue affects multiple versions of Apache Struts.

Details

Module Info

Vulnerability Info

This Medium-severity vulnerability is found in the org.apache.struts:struts2-rest-plugin package in multiple versions of Apache Struts. When a request reaches an action through the REST plugin, ContentTypeInterceptor selects a content-type handler for the request and passes it a reader over the raw request body:

if (request.getContentLength() > 0) {
    InputStream is = request.getInputStream();
    InputStreamReader reader = new InputStreamReader(is);
    handler.toObject(invocation, reader, target);
}
return invocation.invoke();

The only check is that the request declares a positive Content-Length; nothing limits how many characters the handler may read from the reader. The handler deserializes the whole body into memory before the action is invoked, so a client can send an arbitrarily large body and force the server to allocate memory in proportion to it until the heap is exhausted. No additional setting has to be enabled: any application that uses the REST plugin to accept request bodies is exposed in its default configuration. Applications that do not use the REST plugin are not affected.

Mitigation

Only recent versions of Apache Struts are community-supported. Older lines are End-of-Life and will not receive any updates to address this issue.

Users of the affected components should apply one of the following mitigations:

  • Upgrade affected applications to a supported version of Apache Struts.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support.

Credits

  • n0mi1k (finder)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Medium
ID
CVE-2026-104713
PROJECT Affected
Apache Struts
Versions Affected
>=2.1.8 <=2.3.37, >=2.5.0 <=2.5.33, >=6.0.0 <=6.11.0, >=7.0.0 <=7.3.0
NES Versions Affected
Published date
October 6, 2026
≈ Fix date
October 7, 2026
Category
Denial of Service
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Apache Struts
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.