org.apache.struts/struts2-core: Apache Struts: Denial of Service via resource amplification in tag library

cve CVE-2026-104712 3 sources, 3 claims · Watch

Red Hat writes:
org.apache.struts/struts2-core: Apache Struts: Denial of Service via resource amplification in tag library the claim
Severity they disagree
unknown GitHub advisories
important Red Hat
CVSS
7.5 Red Hat
Vendor
Apache Software Foundation NVD
Product
Apache Struts NVD
CWE
CWE-405 GitHub advisories
CWE-405 NVD
CWE-770 Red Hat

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Timeline

2026-10-05first spoke of it: Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request...GitHub advisories
2026-10-05first spoke of it: Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request, allowing an unauthenticated remote attacker to exhaust server CPU and outbound network capacity with sustained low-volume traffic. Applications that do not bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected. This issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.NVD
2026-10-05first spoke of it: org.apache.struts/struts2-core: Apache Struts: Denial of Service via resource amplification in tag libraryRed Hat

What it is to other things

In words only, so not counted until a person confirms one:

affectsapache_software_foundation/apache_struts
NVD says “Apache Software Foundation · Apache Struts”
made_byapache_software_foundation
NVD says “Apache Software Foundation”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
CVSS
cvss
Red Hat7.5
receipt
Source
Red Hat
Its words
7.5
Read by
field:cvss3_score
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-104712",
  "CWE": "CWE-770",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2546055",
  "bugzilla_description": "org.apache.struts/struts2-core: Apache Struts: Denial of Service via resource amplification in tag library",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-05T18:35:41Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-104712.json",
  "severity": "important"
}
—
CVSS vector
cvss_vector
Red HatCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
receipt
Source
Red Hat
Its words
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Read by
field:cvss3_scoring_vector
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-104712",
  "CWE": "CWE-770",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2546055",
  "bugzilla_description": "org.apache.struts/struts2-core: Apache Struts: Denial of Service via resource amplification in tag library",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-05T18:35:41Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-104712.json",
  "severity": "important"
}
—
CWE
cwe
different words
GitHub advisoriesCWE-405
receipt
Source
GitHub advisories
Its words
CWE-405
Read by
field:cwes[].cwe_id
Said since
2026-10-06 00:23 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-104712",
  "cvss": {
    "score": null,
    "vector_string": null
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 0.0,
      "vector_string": null
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-405",
      "name": "Asymmetric Resource Consumption (Amplification)"
    }
  ],
  "description": "Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request, allowing an unauthenticated remote attacker to exhaust server CPU and outbound network capacity with sustained low-volume traffic. Applications that do not bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected.\n\nThis issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0.\n\nUsers are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.",
  "ghsa_id": "GHSA-8536-jvj9-v78f",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-8536-jvj9-v78f",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-8536-jvj9-v78f"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-104712"
    }
  ],
  "nvd_published_at": "2026-10-05T19:17:14Z",
  "published_at": "2026-10-05T21:31:34Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-104712",
    "https://cwiki.apache.org/confluence/display/WW/S2-076",
    "http://www.openwall.com/lists/oss-security/2026/10/05/11",
    "https://github.com/advisories/GHSA-8536-jvj9-v78f"
  ],
  "repository_advisory_url": null,
  "severity": "unknown",
  "source_code_location": "",
  "summary": "Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request...",
  "type": "unreviewed",
  "updated_at": "2026-10-05T21:31:38Z",
  "url": "https://api.github.com/advisories/GHSA-8536-jvj9-v78f",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
CWE
cwe
different words
NVDCWE-405
receipt
Source
NVD
Its words
CWE-405
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCWE-405
2026-10-06 00:34 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.struts:struts2-core",
            "packageURL": "pkg:maven/org.apache.struts/struts2-core",
            "product": "Apache Struts",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "2.5.33",
                "status": "affected",
                "version": "2.5.14",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.11.0",
                "status": "affected",
                "version": "6.0.0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.3.0",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request, allowing an unauthenticated remote attacker to exhaust server CPU and outbound network capacity with sustained low-volume traffic. Applications that do not bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected.\n\nThis issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0.\n\nUsers are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue."
      }
    ],
    "id": "CVE-2026-104712",
    "lastModified": "2026-10-05T20:17:08.940",
    "metrics": {},
    "published": "2026-10-05T19:17:14.630",
    "references": [
      {
        "source": "security@apache.org",
        "url": "https://cwiki.apache.org/confluence/display/WW/S2-076"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.openwall.com/lists/oss-security/2026/10/05/11"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-405"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
different words
Red HatCWE-770
receipt
Source
Red Hat
Its words
CWE-770
Read by
field:CWE
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-104712",
  "CWE": "CWE-770",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2546055",
  "bugzilla_description": "org.apache.struts/struts2-core: Apache Struts: Denial of Service via resource amplification in tag library",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-05T18:35:41Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-104712.json",
  "severity": "important"
}
—
Product
product
NVDApache Struts
receipt
Source
NVD
Its words
Apache Struts
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-06 00:34 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.struts:struts2-core",
            "packageURL": "pkg:maven/org.apache.struts/struts2-core",
            "product": "Apache Struts",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "2.5.33",
                "status": "affected",
                "version": "2.5.14",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.11.0",
                "status": "affected",
                "version": "6.0.0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.3.0",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request, allowing an unauthenticated remote attacker to exhaust server CPU and outbound network capacity with sustained low-volume traffic. Applications that do not bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected.\n\nThis issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0.\n\nUsers are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue."
      }
    ],
    "id": "CVE-2026-104712",
    "lastModified": "2026-10-05T20:17:08.940",
    "metrics": {},
    "published": "2026-10-05T19:17:14.630",
    "references": [
      {
        "source": "security@apache.org",
        "url": "https://cwiki.apache.org/confluence/display/WW/S2-076"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.openwall.com/lists/oss-security/2026/10/05/11"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-405"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
conflict
GitHub advisoriesunknown
receipt
Source
GitHub advisories
Its words
unknown
Read by
field:severity
Said since
2026-10-06 00:23 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-104712",
  "cvss": {
    "score": null,
    "vector_string": null
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 0.0,
      "vector_string": null
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-405",
      "name": "Asymmetric Resource Consumption (Amplification)"
    }
  ],
  "description": "Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request, allowing an unauthenticated remote attacker to exhaust server CPU and outbound network capacity with sustained low-volume traffic. Applications that do not bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected.\n\nThis issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0.\n\nUsers are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.",
  "ghsa_id": "GHSA-8536-jvj9-v78f",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-8536-jvj9-v78f",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-8536-jvj9-v78f"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-104712"
    }
  ],
  "nvd_published_at": "2026-10-05T19:17:14Z",
  "published_at": "2026-10-05T21:31:34Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-104712",
    "https://cwiki.apache.org/confluence/display/WW/S2-076",
    "http://www.openwall.com/lists/oss-security/2026/10/05/11",
    "https://github.com/advisories/GHSA-8536-jvj9-v78f"
  ],
  "repository_advisory_url": null,
  "severity": "unknown",
  "source_code_location": "",
  "summary": "Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request...",
  "type": "unreviewed",
  "updated_at": "2026-10-05T21:31:38Z",
  "url": "https://api.github.com/advisories/GHSA-8536-jvj9-v78f",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Severity
severity
conflict
Red Hatimportant
A flaw that can easily compromise confidentiality, integrity or availability.
receipt
Source
Red Hat
Its words
important
Read by
field:severity
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-104712",
  "CWE": "CWE-770",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2546055",
  "bugzilla_description": "org.apache.struts/struts2-core: Apache Struts: Denial of Service via resource amplification in tag library",
  "cvss3_score": "7.5",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-05T18:35:41Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-104712.json",
  "severity": "important"
}
high
Status
status
NVDReceived
receipt
Source
NVD
Its words
Received
Read by
field:cve.vulnStatus
Said since
2026-10-06 00:34 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.struts:struts2-core",
            "packageURL": "pkg:maven/org.apache.struts/struts2-core",
            "product": "Apache Struts",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "2.5.33",
                "status": "affected",
                "version": "2.5.14",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.11.0",
                "status": "affected",
                "version": "6.0.0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.3.0",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request, allowing an unauthenticated remote attacker to exhaust server CPU and outbound network capacity with sustained low-volume traffic. Applications that do not bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected.\n\nThis issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0.\n\nUsers are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue."
      }
    ],
    "id": "CVE-2026-104712",
    "lastModified": "2026-10-05T20:17:08.940",
    "metrics": {},
    "published": "2026-10-05T19:17:14.630",
    "references": [
      {
        "source": "security@apache.org",
        "url": "https://cwiki.apache.org/confluence/display/WW/S2-076"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.openwall.com/lists/oss-security/2026/10/05/11"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-405"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDApache Software Foundation
receipt
Source
NVD
Its words
Apache Software Foundation
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-06 00:34 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.maven.apache.org/maven2",
            "defaultStatus": "unaffected",
            "packageName": "org.apache.struts:struts2-core",
            "packageURL": "pkg:maven/org.apache.struts/struts2-core",
            "product": "Apache Struts",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "2.5.33",
                "status": "affected",
                "version": "2.5.14",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "6.11.0",
                "status": "affected",
                "version": "6.0.0",
                "versionType": "semver"
              },
              {
                "lessThanOrEqual": "7.3.0",
                "status": "affected",
                "version": "7.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request, allowing an unauthenticated remote attacker to exhaust server CPU and outbound network capacity with sustained low-volume traffic. Applications that do not bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected.\n\nThis issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0.\n\nUsers are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue."
      }
    ],
    "id": "CVE-2026-104712",
    "lastModified": "2026-10-05T20:17:08.940",
    "metrics": {},
    "published": "2026-10-05T19:17:14.630",
    "references": [
      {
        "source": "security@apache.org",
        "url": "https://cwiki.apache.org/confluence/display/WW/S2-076"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.openwall.com/lists/oss-security/2026/10/05/11"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-405"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

org.apache.struts/struts2-core: Apache Struts: Denial of Service via resource amplification in tag library
zetlyn/cve-redhat · 2026-10-05
cvss 7.5 cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H cwe CWE-770 severity important source
Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request, allowing an unauthenticated remote attacker to exhaust server CPU and outbound network capacity with sustained low-volume traffic. Applications that do not bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected. This issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.
zetlyn/cve-nvd · 2026-10-05
cwe CWE-405 product Apache Struts status Received vendor Apache Software Foundation source
Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request...
zetlyn/cve-ghsa · 2026-10-05
cwe CWE-405 severity unknown source