Home

Description

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.

PUBLISHED Reserved 2025-11-11 | Published 2025-12-01 | Updated 2025-12-01 | Assigner apache

Problem types

CWE-459 Incomplete Cleanup

Product status

Default status
unaffected

2.0.0 (semver)
affected

7.0.0 (semver)
affected

Credits

Nicolas Fournier reporter

References

www.openwall.com/lists/oss-security/2025/12/01/2

cwiki.apache.org/confluence/display/WW/S2-068 vendor-advisory

cve.org (CVE-2025-64775)

nvd.nist.gov (CVE-2025-64775)

Download JSON