This issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0.
Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://cwiki.apache.org/confluence/display/WW/S2-076 |
|
Mon, 05 Oct 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request, allowing an unauthenticated remote attacker to exhaust server CPU and outbound network capacity with sustained low-volume traffic. Applications that do not bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected. This issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue. | |
| Title | Apache Struts: Disproportionate response size when rendering BigDecimal request parameters | |
| Weaknesses | CWE-405 | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-10-05T19:08:41.655Z
Reserved: 2026-10-02T10:54:11.636Z
Link: CVE-2026-104712
No data.
Status : Received
Published: 2026-10-05T19:17:14.630
Modified: 2026-10-05T19:17:14.630
Link: CVE-2026-104712
No data.
OpenCVE Enrichment
Updated: 2026-10-05T19:30:21Z
-
CWE-405
Asymmetric Resource Consumption (Amplification)