Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104712— Apache Struts: Disproportionate response size when rendering BigDecimal request parameters

Quick assessment

Affected
Apache Software Foundation Apache Struts
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Struts 存在非对称资源消耗(放大)漏洞。当请求参数被绑定到任意精度小数( )属性,并且该属性随后通过 Struts 标签库进行渲染时,框架可能会生成比请求大多个数量级的响应。这使得未经身份验证的远程攻击者能够通过持续的低流量请求,耗尽服务器的 CPU 资源和 outbound 网络带宽。 对于未将请求参数绑定到 属性,或从未通过 Struts 标签库渲染此类属性的应用程序,不受此漏洞影响。 此漏洞影响以下 Apache Struts 版本: 2.5.14 至 2.5.33 6.0.0 至 6.1

AI Predicted 7.5 Difficulty: Easy

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 3

VendorProduct Version RangeStatus
Apache Software Foundation Apache Struts 2.5.14≤ 2.5.33 affected
6.0.0≤ 6.11.0 affected
7.0.0≤ 7.3.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104712

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Struts: Disproportionate response size when rendering BigDecimal request parameters
Source: CVE Program / CVE List V5
Vulnerability Description
Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request, allowing an unauthenticated remote attacker to exhaust server CPU and outbound network capacity with sustained low-volume traffic. Applications that do not bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected. This issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
不对称的资源消耗(放大攻击)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Struts 2.5.14 ~ 2.5.33 -

II. Public POCs for CVE-2026-104712

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104712

请登录查看更多情报信息。

Other References for CVE-2026-104712 (1)

Same Patch Batch · Apache Software Foundation · 2026-10-05 · 4 CVEs total

CVE-2026-104714 Apache Struts: Shared message formatter exposes date and time values across concurrent req
CVE-2026-104713 Apache Struts: Unbounded request body read in the REST plugin
CVE-2026-104711 Apache Struts: OGNL injection in the legacy RESTful action mapper

IV. Related Vulnerabilities

V. Comments for CVE-2026-104712

No comments yet


Leave a comment