Apache Struts 存在非对称资源消耗(放大)漏洞。当请求参数被绑定到任意精度小数( )属性,并且该属性随后通过 Struts 标签库进行渲染时,框架可能会生成比请求大多个数量级的响应。这使得未经身份验证的远程攻击者能够通过持续的低流量请求,耗尽服务器的 CPU 资源和 outbound 网络带宽。 对于未将请求参数绑定到 属性,或从未通过 Struts 标签库渲染此类属性的应用程序,不受此漏洞影响。 此漏洞影响以下 Apache Struts 版本: 2.5.14 至 2.5.33 6.0.0 至 6.1
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Struts | 2.5.14≤ 2.5.33 |
affected |
6.0.0≤ 6.11.0 |
affected | ||
7.0.0≤ 7.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Struts | 2.5.14 ~ 2.5.33 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104714 | Apache Struts: Shared message formatter exposes date and time values across concurrent req | |
| CVE-2026-104713 | Apache Struts: Unbounded request body read in the REST plugin | |
| CVE-2026-104711 | Apache Struts: OGNL injection in the legacy RESTful action mapper |
No comments yet