Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion.
This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3.
Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.
It's related to https://cve.org/CVERecord?id=CVE-2025-64775 - this CVE addresses missing affected version 6.7.4
Metrics
Affected Vendors & Products
References
History
Wed, 10 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue. It's related to https://cve.org/CVERecord?id=CVE-2025-64775 - this CVE addresses missing affected version 6.7.4 | |
| Title | Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS) - version ranges fixed | |
| Weaknesses | CWE-459 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published: 2025-12-10T09:32:58.536Z
Updated: 2025-12-10T09:32:58.536Z
Reserved: 2025-12-07T08:25:45.422Z
Link: CVE-2025-66675
No data.
Status : Received
Published: 2025-12-10T10:16:02.170
Modified: 2025-12-10T10:16:02.170
Link: CVE-2025-66675
No data.