Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request, allowing an unauthenticated remote attacker to exhaust server CPU and outbound network capacity with sustained low-volume traffic. Applications that do not bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected. This issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.

zetlyn/cve-nvd vulnerability cve CVE-2026-104712 known 2026-10-05

https://nvd.nist.gov/vuln/detail/CVE-2026-104712

Properties

cweCWE-405
receipt
Source
NVD
Its words
CWE-405
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCWE-405
2026-10-06 00:34 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.struts:struts2-core",
            "packageURL": "pkg:maven/org.apache.struts/struts2-core",
            "product": "Apache Struts",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "2.5.33",
                "status": "affected",
                "version": "2.5.14",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.11.0",
                "status": "affected",
                "version": "6.0.0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.3.0",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request, allowing an unauthenticated remote attacker to exhaust server CPU and outbound network capacity with sustained low-volume traffic. Applications that do not bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected.\n\nThis issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0.\n\nUsers are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue."
      }
    ],
    "id": "CVE-2026-104712",
    "lastModified": "2026-10-05T20:17:08.940",
    "metrics": {},
    "published": "2026-10-05T19:17:14.630",
    "references": [
      {
        "source": "security@apache.org",
        "url": "https://cwiki.apache.org/confluence/display/WW/S2-076"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.openwall.com/lists/oss-security/2026/10/05/11"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-405"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
productApache Struts
receipt
Source
NVD
Its words
Apache Struts
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-06 00:34 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.struts:struts2-core",
            "packageURL": "pkg:maven/org.apache.struts/struts2-core",
            "product": "Apache Struts",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "2.5.33",
                "status": "affected",
                "version": "2.5.14",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.11.0",
                "status": "affected",
                "version": "6.0.0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.3.0",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request, allowing an unauthenticated remote attacker to exhaust server CPU and outbound network capacity with sustained low-volume traffic. Applications that do not bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected.\n\nThis issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0.\n\nUsers are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue."
      }
    ],
    "id": "CVE-2026-104712",
    "lastModified": "2026-10-05T20:17:08.940",
    "metrics": {},
    "published": "2026-10-05T19:17:14.630",
    "references": [
      {
        "source": "security@apache.org",
        "url": "https://cwiki.apache.org/confluence/display/WW/S2-076"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.openwall.com/lists/oss-security/2026/10/05/11"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-405"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
statusReceived
receipt
Source
NVD
Its words
Received
Read by
field:cve.vulnStatus
Said since
2026-10-06 00:34 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.struts:struts2-core",
            "packageURL": "pkg:maven/org.apache.struts/struts2-core",
            "product": "Apache Struts",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "2.5.33",
                "status": "affected",
                "version": "2.5.14",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.11.0",
                "status": "affected",
                "version": "6.0.0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.3.0",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request, allowing an unauthenticated remote attacker to exhaust server CPU and outbound network capacity with sustained low-volume traffic. Applications that do not bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected.\n\nThis issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0.\n\nUsers are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue."
      }
    ],
    "id": "CVE-2026-104712",
    "lastModified": "2026-10-05T20:17:08.940",
    "metrics": {},
    "published": "2026-10-05T19:17:14.630",
    "references": [
      {
        "source": "security@apache.org",
        "url": "https://cwiki.apache.org/confluence/display/WW/S2-076"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.openwall.com/lists/oss-security/2026/10/05/11"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-405"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
vendorApache Software Foundation
receipt
Source
NVD
Its words
Apache Software Foundation
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-06 00:34 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.struts:struts2-core",
            "packageURL": "pkg:maven/org.apache.struts/struts2-core",
            "product": "Apache Struts",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "2.5.33",
                "status": "affected",
                "version": "2.5.14",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.11.0",
                "status": "affected",
                "version": "6.0.0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.3.0",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request, allowing an unauthenticated remote attacker to exhaust server CPU and outbound network capacity with sustained low-volume traffic. Applications that do not bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected.\n\nThis issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0.\n\nUsers are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue."
      }
    ],
    "id": "CVE-2026-104712",
    "lastModified": "2026-10-05T20:17:08.940",
    "metrics": {},
    "published": "2026-10-05T19:17:14.630",
    "references": [
      {
        "source": "security@apache.org",
        "url": "https://cwiki.apache.org/confluence/display/WW/S2-076"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.openwall.com/lists/oss-security/2026/10/05/11"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-405"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}

Text

Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request, allowing an unauthenticated remote attacker to exhaust server CPU and outbound network capacity with sustained low-volume traffic. Applications that do not bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected. This issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.