Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104713— Apache Struts: Unbounded request body read in the REST plugin

Quick assessment

Affected
Apache Software Foundation Apache Struts
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Struts REST 插件中存在资源分配无限制或无节流措施的漏洞。该漏洞允许将请求体无限制地读入内存,即对接受的请求大小不设任何上限。因此,单个请求可能导致服务器根据其大小分配相应内存,从而耗尽 Java 堆内存,导致其他用户无法获得服务(拒绝服务)。无需启用任何额外配置即可利用此漏洞。不使用 REST 插件的应用程序不受此漏洞影响。 受影响的产品版本为:Apache Struts 2.1.8 至 2.3.37、2.5.0 至 2.5.33、6.0.0 至 6.11.0、7.0.0 至 7.3.0。

AI Predicted 7.5 Difficulty: Easy

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 4

VendorProduct Version RangeStatus
Apache Software Foundation Apache Struts 2.1.8≤ 2.3.37 affected
2.5.0≤ 2.5.33 affected
6.0.0≤ 6.11.0 affected
7.0.0≤ 7.3.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104713

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Struts: Unbounded request body read in the REST plugin
Source: CVE Program / CVE List V5
Vulnerability Description
Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin. A request body is read into memory without any bound on how much will be accepted, so a single request can cause the server to allocate memory in proportion to its size, exhausting the Java heap and denying service to other users. No additional setting has to be enabled. Applications that do not use the REST plugin are not affected. This issue affects Apache Struts: from 2.1.8 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Struts 2.1.8 ~ 2.3.37 -

II. Public POCs for CVE-2026-104713

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104713

请登录查看更多情报信息。

Other References for CVE-2026-104713 (1)

Same Patch Batch · Apache Software Foundation · 2026-10-05 · 4 CVEs total

CVE-2026-104714 Apache Struts: Shared message formatter exposes date and time values across concurrent req
CVE-2026-104712 Apache Struts: Disproportionate response size when rendering BigDecimal request parameters
CVE-2026-104711 Apache Struts: OGNL injection in the legacy RESTful action mapper

IV. Related Vulnerabilities

V. Comments for CVE-2026-104713

No comments yet


Leave a comment