CVE-2026-104713 Overview
CVE-2026-104713 is a resource exhaustion vulnerability in the Apache Struts REST plugin. The plugin reads request bodies into memory without enforcing a size limit. A single large request can allocate Java heap memory proportional to its size, leading to heap exhaustion and denial of service for other users. No special configuration is required for exploitation. Applications that do not use the REST plugin are not affected. The flaw is tracked as CWE-770: Allocation of Resources Without Limits or Throttling and is addressed in Apache Struts 6.12.0 and 7.4.0.
Critical Impact
An authenticated attacker can send a single oversized request to a REST endpoint and exhaust the server's Java heap, denying service to legitimate users.
Affected Products
- Apache Struts 2.1.8 through 2.3.37
- Apache Struts 2.5.0 through 2.5.33
- Apache Struts 6.0.0 through 6.11.0 and 7.0.0 through 7.3.0
Discovery Timeline
- 2026-10-05 - CVE-2026-104713 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-104713
Vulnerability Analysis
The Apache Struts REST plugin accepts HTTP request bodies and buffers them in memory for parsing and dispatch. The plugin does not impose an upper bound on the number of bytes it will read before processing. An attacker who can reach a REST endpoint can submit a request with an inflated body, forcing the JVM to allocate memory proportional to the payload size. Repeated or sufficiently large requests exhaust the Java heap, triggering OutOfMemoryError conditions and halting request processing for all tenants of the application server.
The issue requires only low-privilege access and no user interaction. Exploitation does not require authentication bypass or chaining with other vulnerabilities. The impact is limited to availability; confidentiality and integrity of application data are not affected.
Root Cause
The root cause is missing input size validation in the REST plugin's request body ingestion path. The code reads the body stream fully into memory before applying any dispatch logic, violating the principle of bounding untrusted input. This maps directly to CWE-770, where a resource is allocated based on attacker-controlled size without quota enforcement.
Attack Vector
The attack is network-based and targets any Struts application that loads the REST plugin. The attacker sends an HTTP request to a REST-handled URL with an unusually large body payload. The server attempts to buffer the entire body, consuming heap memory in proportion to the declared or streamed content length. A small number of concurrent requests, or a single sufficiently large request, can push the JVM past its configured maximum heap size.
See the Apache Struts S2-077 advisory and the OpenWall oss-security notification for vendor-published technical details. No verified public proof-of-concept code is available at the time of writing.
Detection Methods for CVE-2026-104713
Indicators of Compromise
- HTTP requests to REST plugin endpoints with abnormally large Content-Length headers or chunked bodies exceeding typical application payload sizes.
- Repeated java.lang.OutOfMemoryError: Java heap space entries in Struts application logs correlated with inbound REST traffic.
- Sudden JVM garbage collection pressure, full GC storms, or process restarts on servers hosting the Struts REST plugin.
Detection Strategies
- Inspect reverse proxy and web application firewall logs for POST, PUT, or PATCH requests to REST routes with body sizes exceeding a defined threshold (for example, 1 MB).
- Correlate web server access logs with JVM heap metrics to identify oversized requests immediately preceding memory spikes.
- Monitor for a low rate of large-body requests originating from a single source IP, which can indicate deliberate heap exhaustion attempts.
Monitoring Recommendations
- Enable JVM metrics export (heap used, GC pause time, allocation rate) to a centralized observability platform.
- Alert on application process restarts and OutOfMemoryError log patterns across all Struts hosts.
- Baseline normal request-body sizes per REST endpoint and alert on statistical outliers.
How to Mitigate CVE-2026-104713
Immediate Actions Required
- Upgrade Apache Struts to 6.12.0 or 7.4.0, which enforce bounds on REST request body size.
- Inventory applications that load the Struts REST plugin and prioritize them for patching; applications without the plugin are not affected.
- Enforce request-body size limits at the reverse proxy or load balancer in front of Struts applications as a compensating control.
Patch Information
The Apache Struts project has released fixed versions 6.12.0 and 7.4.0. Earlier branches (2.3.x, 2.5.x) remain affected and should be migrated to a supported release line. Patch details are published in the Apache Struts S2-077 advisory.
Workarounds
- Configure the fronting web server, reverse proxy, or WAF to reject HTTP requests with bodies larger than the maximum expected by the application.
- Restrict access to REST plugin endpoints to authenticated and trusted clients using network ACLs or ingress authentication where feasible.
- Reduce the JVM maximum heap size impact by running multiple smaller Struts instances behind a load balancer so a single exhausted process does not take down the service.
# Example: limit request body size to 1 MB in nginx fronting a Struts application
http {
client_max_body_size 1m;
server {
listen 443 ssl;
location /rest/ {
client_max_body_size 1m;
proxy_pass http://struts_backend;
}
}
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.