Radar records CVE-2026-104712, disclosed on October 5, 2026 and rated moderate severity. According to the text, when a request parameter is bound to an arbitrary-precision java.math.BigDecimal property and that property is later rendered by the Struts tag library, the framework can produce a response much larger than the input, which is an asymmetric resource consumption issue. The versions listed as affected are Apache Struts 2.5.14 through 2.5.33, 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0. The content is an automatic translation of a maintainer post on the oss-sec feed. To verify, consult the original advisory by its CVE identifier in the 2026 oss-sec archive and check the list of fixed versions on the official Apache Struts project site, since the source text does not state fixed versions. Rota Nacional does not patch third-party libraries.
Cyber ·
CVE-2026-104712: Apache Struts can produce a disproportionate response with BigDecimal parameters
A moderate-severity advisory, published on October 5, 2026 on the oss-sec feed, describing resource amplification in Apache Struts when BigDecimal parameters are rendered by the tag library.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.