CVE-2026-104712

Denial of Service
Affects
Apache Struts
in
Apache Struts
No items found.
Versions
>=2.5.14 <=2.5.33, >=6.0.0 <=6.11.0, >=7.0.0 <=7.3.0

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Apache Struts is a popular open-source web application framework for developing Java EE web applications. Its type conversion layer turns request parameters into typed action properties and converts those properties back into strings when the Struts tag library renders them in a response.

A denial of service vulnerability (CVE-2026-104712) has been identified in the Struts string type converter, which allows attackers to make the server produce a response many orders of magnitude larger than the request by submitting a BigDecimal value with a very large scale. Sustained low-volume traffic can exhaust server CPU and outbound network capacity without authentication.

Per OWASP: The Denial of Service (DoS) attack is focused on making a resource (site, application, server) unavailable for the purpose it was designed.

This issue affects multiple versions of Apache Struts, including the End-of-Life 2.5.x line.

‍

Details

Module Info

Vulnerability Info

This High-severity vulnerability is found in the org.apache.struts:struts2-core package in multiple versions of Apache Struts. When an action binds a request parameter to a java.math.BigDecimal property and a Struts tag later renders that property, the value is turned back into text by StringConverter.convertToString in com.opensymphony.xwork2.conversion.impl.StringConverter:

protected String convertToString(Locale locale, Object value) {
    if (Number.class.isInstance(value)) {
        NumberFormat format = NumberFormat.getNumberInstance(locale);
        format.setGroupingUsed(false);
        Object fixedValue = value;
        if (BigDecimal.class.isInstance(value) || Double.class.isInstance(value) || Float.class.isInstance(value)) {
            format.setMaximumFractionDigits(Integer.MAX_VALUE);
            if (Float.class.isInstance(value)) {
                fixedValue = Double.valueOf(value.toString());
            }
        }
        return format.format(fixedValue);
    } else {
        return Objects.toString(value, null);
    }
}

Setting maximumFractionDigits to Integer.MAX_VALUE places no limit on the number of fraction digits DecimalFormat writes, so a BigDecimal is printed out to its full scale. The scale is chosen by the client: a short parameter in scientific notation such as 1E-100000 parses into a BigDecimal with a scale of 100,000, and rendering it produces a decimal string of about 100,000 characters. Each such request therefore costs the server the CPU time to format the number and the bandwidth to send about 100,000 characters for a parameter value of nine characters, which lets an unauthenticated attacker degrade or exhaust the server with modest traffic. Applications that never bind request parameters to BigDecimal properties, or never render such a property through the Struts tag library, are not affected.

‍

Mitigation

Only recent versions of Apache Struts are community-supported. Older lines are End-of-Life and will not receive any updates to address this issue.

As a workaround, applications can register their own type converter for java.math.BigDecimal that bounds the value's scale before it is rendered, by adding an entry for it to struts-conversion.properties in the root of the classpath (on the 2.5.x line the file is named xwork-conversion.properties).

Users of the affected components should apply one of the following mitigations:

  • Upgrade affected applications to a supported version of Apache Struts.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support.

‍

Credits

  • 0xCc.zhang (finder)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
High
ID
CVE-2026-104712
PROJECT Affected
Apache Struts
Versions Affected
>=2.5.14 <=2.5.33, >=6.0.0 <=6.11.0, >=7.0.0 <=7.3.0
NES Versions Affected
Published date
October 6, 2026
≈ Fix date
October 7, 2026
Category
Denial of Service
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Apache Struts
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.