CVE-2026-104713

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin. A request body is read into memory without any bound on how much will be accepted, so a single request can cause the server to allocate memory in proportion to its size, exhausting the Java heap and denying service to other users. No additional setting has to be enabled. Applications that do not use the REST plugin are not affected. This issue affects Apache Struts: from 2.1.8 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-05: 110-05
Referenced assets1 URL
By indicator
Full discourse1 post
  • ThreatWire@ThreatWire_

    🚨 SECURITY UPDATE: Apache Struts 7.4.0 and 6.12.0 fix four vulnerabilities (S2-075 to S2-078). ➡️ CVE-2026-104713 (Important): the REST plugin reads request bodies without a size limit, allowing heap exhaustion and denial of service. 7.4.0 adds a 2 MB default limit. ➡️ CVE-2026-104711 (Moderate): OGNL injection through the legacy RESTful action mapper, which can lead to remote code execution. On 7.x, only deployments with the OGNL allowlist disabled are affected. ➡️ CVE-2026-104712 / CVE-2026-104714 (Moderate): a BigDecimal rendering DoS and a shared date formatter race that can cause information disclosure or DoS. ⚠️ No official CVSS yet. Not in CISA KEV, and no exploitation reported. 🔴 Upgrade to Struts 7.4.0 or 6.12.0. The 2.x branches are end-of-life: plan a migration. Full breakdown 👉 https://www.threatwire.tech/news/apache-struts-7-4-0-fixes-four-security-flaws #CyberSecurity #InfoSec #ApacheStruts #Java

    01091601
    1.7K followersView on X

Explore more