Skip to content
THREATWIRE

CVE

MediumNo PoC

CVE-2026-104712

Disproportionate BigDecimal response expansion (DoS)

Apache Struts S2-076 says binding request parameters to java.math.BigDecimal and rendering them through the Struts tag library can produce a response many orders of magnitude larger than the request, exhausting CPU and network capacity. Apache rates it Moderate. Fixed in 7.4.0 and 6.12.0.

CVSS
Unknown
Vector
Not recorded
Class
DoS
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
Apache
Products
Apache Struts
Affected
Struts 2.5.14 through 2.5.33 (EOL); 6.0.0 through 6.11.0; 7.0.0 through 7.3.0. Struts 2.3.x and earlier are not affected.
Fixed
Struts 7.4.0 or later, or Struts 6.12.0 or later on the 6.x line.
CWE
Not recorded
Published
5 Oct 2026
Updated
5 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-104712 is described in Apache Struts Security Bulletin S2-076. When a request parameter is bound to a java.math.BigDecimal property and that property is rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the request. Apache says a remote attacker needs no authentication and no significant bandwidth of their own; sustained low-volume traffic can saturate server CPU and outbound network capacity. The maximum security rating is Moderate.

Applications that do not bind request parameters to BigDecimal properties, or that never render such a property through the Struts tag library, are not affected. Responses produced by the JSON plugin and the REST plugin are not affected. Other numeric types such as double, float, long, and int are not affected. Struts 2.3.x and earlier are not affected.

Affected software named by Apache is Struts 2.5.14 through 2.5.33 (EOL), 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0. Upgrade to Struts 7.4.0 or later, or to Struts 6.12.0 or later on the 6.x line. As a workaround, Apache says to register an application-supplied type converter for java.math.BigDecimal that bounds the value's scale before it is rendered, via struts-conversion.properties (or xwork-conversion.properties on EOL 2.5.x).

Apache has not published a CVSS score. NVD and CVE.org have no populated record yet, no GHSA was found, and CISA KEV does not list the CVE. No public PoC tagged to this CVE id was confirmed. Exploitation in the wild is not confirmed.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-104712