Skip to content
THREATWIRE

CVE

HighNo PoC

CVE-2026-104713

Unbounded REST plugin request body read (DoS)

Apache Struts S2-077 says the optional REST plugin reads a request body into memory without a bound, so a single request can exhaust the heap. Apache rates it Important. Fixed in 7.4.0 and 6.12.0 with a default 2 MB body limit. Not in CISA KEV.

CVSS
Unknown
Vector
Not recorded
Class
DoS
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
Apache
Products
Apache Struts, Apache Struts REST plugin
Affected
Struts 2.1.8 through 2.3.37 (EOL); 2.5.0 through 2.5.33 (EOL); 6.0.0 through 6.11.0; 7.0.0 through 7.3.0. Earlier releases without the REST plugin are not affected. Applications that do not use the REST plugin are not affected.
Fixed
Struts 7.4.0 or later, or Struts 6.12.0 or later on the 6.x line.
CWE
Not recorded
Published
5 Oct 2026
Updated
5 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-104713 is described in Apache Struts Security Bulletin S2-077. When an application uses the REST plugin, a request carrying a body has that body read into memory without any bound on how much will be accepted. A single request can therefore allocate memory in proportion to the body size, exhausting the heap and denying service to other users. Apache rates the maximum security impact as Important.

Apache says this is the same class of issue as S2-072 and S2-073, in a component those fixes did not cover. The issue is confined to the optional REST plugin. Applications that do not use it are not affected. Unlike S2-072, no additional setting must be enabled: applications using the plugin to accept request bodies are exposed in the default configuration.

Affected ranges named by Apache are Struts 2.1.8 through 2.3.37 (EOL), 2.5.0 through 2.5.33 (EOL), 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0. Upgrade to Struts 7.4.0 or later, or to Struts 6.12.0 or later on the 6.x line. Fixed releases limit the REST plugin request body to 2,097,152 characters (2 MB) by default via struts.rest.content.maxLength; oversized bodies are rejected before the action runs. Apache states there is no configuration-only mitigation inside Struts; until an upgrade, enforce a maximum request body size in the reverse proxy or servlet container for endpoints that accept bodies.

Apache has not published a CVSS score. NVD and CVE.org have no populated record yet, no GHSA was found, and CISA KEV does not list the CVE. No public PoC tagged to this CVE id was confirmed. Exploitation in the wild is not confirmed.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-104713