CVE-2026-104712

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request, allowing an unauthenticated remote attacker to exhaust server CPU and outbound network capacity with sustained low-volume traffic. Applications that do not bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected. This issue affects Apache Struts: from 2.5.14 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-405

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-05: 110-05
Referenced assets1 URL
By indicator
Full discourse1 post
  • ThreatWire@ThreatWire_

    🚨 SECURITY UPDATE: Apache Struts 7.4.0 and 6.12.0 fix four vulnerabilities (S2-075 to S2-078). ➡️ CVE-2026-104713 (Important): the REST plugin reads request bodies without a size limit, allowing heap exhaustion and denial of service. 7.4.0 adds a 2 MB default limit. ➡️ CVE-2026-104711 (Moderate): OGNL injection through the legacy RESTful action mapper, which can lead to remote code execution. On 7.x, only deployments with the OGNL allowlist disabled are affected. ➡️ CVE-2026-104712 / CVE-2026-104714 (Moderate): a BigDecimal rendering DoS and a shared date formatter race that can cause information disclosure or DoS. ⚠️ No official CVSS yet. Not in CISA KEV, and no exploitation reported. 🔴 Upgrade to Struts 7.4.0 or 6.12.0. The 2.x branches are end-of-life: plan a migration. Full breakdown 👉 https://www.threatwire.tech/news/apache-struts-7-4-0-fixes-four-security-flaws #CyberSecurity #InfoSec #ApacheStruts #Java

    01091601
    1.7K followersView on X

Explore more