According to the advisory published on October 5, 2026 by Lukasz Lenart on the oss-sec list, the flaw is identified as CVE-2026-104713 and has important severity. The Apache Struts REST plugin reads a request body into memory with no limit on the accepted volume, so a single request can make the server allocate memory excessively. The advisory lists Apache Struts versions 2.1.8 to 2.3.37, 2.5.0 to 2.5.33, 6.0.0 to 6.11.0 and 7.0.0 to 7.3.0 as affected. The text received is a machine translation and, in this copy, does not state a fixed version; consult the original advisory and the project's official documentation.
To check whether your organization runs any of these ranges, inventory your Java applications, confirm the Struts version and whether the REST plugin is present. If the application is exposed, consider request size limits at the entry layer, such as a load balancer or reverse proxy, until the official fix is applied. These are general defensive measures and do not depend on the Rota Nacional platform.
Relevance to Rota Nacional: the platform does not patch or protect Struts applications, and this item does not describe any Rota feature. If you use AI to study the advisory or draft a response plan, do not paste logs, configurations, credentials or user personal data into the prompt. Remove or replace such data before sending. On Rota, personal data detection runs before any model executes, and the organization's policy can apply placeholders, removal or a block, but this does not replace data hygiene on your side.