Skip to main content
Vulnerability Database/CVE-2026-104712

CVE-2026-104712: Apache Struts DoS Amplification Vulnerability

CVE-2026-104712 is a denial of service amplification flaw in Apache Struts that allows attackers to exhaust server resources through BigDecimal property exploitation. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-104712 Overview

CVE-2026-104712 is an asymmetric resource consumption (amplification) vulnerability in Apache Struts tracked as [CWE-405]. The flaw lets an unauthenticated remote attacker send small HTTP requests that trigger disproportionately large responses. When a request parameter binds to a java.math.BigDecimal property and that property is rendered through the Struts tag library, the framework can emit output many orders of magnitude larger than the input. Sustained low-volume traffic can exhaust CPU and outbound network capacity on the target server. The issue affects Apache Struts 2.5.14 through 2.5.33, 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0.

Critical Impact

Unauthenticated attackers can exhaust server CPU and outbound bandwidth with minimal request volume, causing denial of service on exposed Struts applications.

Affected Products

  • Apache Struts 2.5.14 through 2.5.33
  • Apache Struts 6.0.0 through 6.11.0
  • Apache Struts 7.0.0 through 7.3.0

Discovery Timeline

  • 2026-10-05 - CVE-2026-104712 published to NVD
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-104712

Vulnerability Analysis

The vulnerability is a resource amplification flaw in the interaction between Struts parameter binding and the tag rendering layer. Apache Struts accepts arbitrary-precision decimal values when a request parameter maps to a java.math.BigDecimal application property. An attacker can supply a compact scientific-notation value such as 1E1000000 that occupies only a handful of bytes on the wire. When the framework later renders that property through the Struts tag library, the value is expanded to its full decimal representation, producing a response payload millions of times larger than the request.

The asymmetry between input size and processing cost creates two concurrent pressures on the server. CPU cycles are consumed by the string formatting of the oversized decimal, and outbound network capacity is saturated by the resulting response bytes. Because the attack requires no authentication and no complex payload, a small number of concurrent clients can degrade or disable the service.

Root Cause

The root cause is the lack of bounds enforcement on BigDecimal values accepted through parameter binding and subsequently materialized by tag rendering. Struts trusts the arbitrary precision of the Java type, so a scale or exponent that a developer never intended is accepted and later expanded in full. Applications that do not bind request parameters to BigDecimal properties, or that never render such a property through the Struts tag library, are not affected.

Attack Vector

The attack vector is network-based and requires no credentials or user interaction. An unauthenticated attacker submits a crafted HTTP request to any endpoint whose action binds a parameter to a BigDecimal property and whose view renders that property via a Struts tag. The attacker repeats low-rate requests to amplify the impact. See the Apache Security Advisory S2-076 and the Openwall OSS Security mailing list post for authoritative technical details.

Detection Methods for CVE-2026-104712

Indicators of Compromise

  • HTTP request parameters containing decimal values with large exponents, such as values matching the pattern [0-9]+[eE][0-9]{3,}.
  • Response payloads from Struts endpoints that are several orders of magnitude larger than their corresponding requests.
  • Sudden sustained CPU saturation on Struts application servers coinciding with low-volume inbound traffic.
  • Outbound bandwidth spikes from application nodes without matching user session growth.

Detection Strategies

  • Inspect web access logs for request/response byte ratios that deviate sharply from baseline on action endpoints that use BigDecimal properties.
  • Deploy web application firewall rules that reject numeric parameters with absolute exponents above an application-appropriate limit.
  • Correlate CPU and outbound bandwidth metrics with request rate to identify amplification patterns independent of request volume.

Monitoring Recommendations

  • Alert on Apache Struts versions in the vulnerable ranges discovered through software inventory scans.
  • Monitor JVM thread and CPU profiles for sustained time spent in BigDecimal.toPlainString or related formatting routines.
  • Track egress bandwidth per application pod or host and alert on sustained deviation from baseline.

How to Mitigate CVE-2026-104712

Immediate Actions Required

  • Upgrade Apache Struts to version 6.12.0 or 7.4.0, which remediate the amplification issue.
  • Inventory running applications for use of BigDecimal properties bound to request parameters and rendered through Struts tags.
  • Place rate limiting and request-size inspection in front of exposed Struts endpoints until patching is complete.

Patch Information

The Apache Struts project fixed CVE-2026-104712 in versions 6.12.0 and 7.4.0. Users on the 2.5.x branch should plan migration, as that branch is reaching end of life and may not receive a dedicated patch. Refer to Apache Security Advisory S2-076 for upgrade guidance and backport notes.

Workarounds

  • Change vulnerable action properties from BigDecimal to a bounded numeric type such as long or double where precision permits.
  • Remove or replace Struts tag rendering of BigDecimal properties with a formatter that enforces a maximum scale and precision.
  • Add server-side validation that rejects numeric parameters whose exponent or digit count exceeds a defined threshold.
  • Enforce response size limits at the reverse proxy or ingress layer to cap amplification impact.
bash
# Example ModSecurity rule to block oversized numeric exponents in parameters
SecRule ARGS "@rx ^[+-]?[0-9]+(\.[0-9]+)?[eE][+-]?[0-9]{3,}$" \
    "id:1049712,phase:2,deny,status:400,msg:'Blocked oversized decimal exponent (CVE-2026-104712)'"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.