Home

Description

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue. It's related to  https://cve.org/CVERecord?id=CVE-2025-64775  - this CVE addresses missing affected version 6.7.4

PUBLISHED Reserved 2025-12-07 | Published 2025-12-10 | Updated 2025-12-10 | Assigner apache

Problem types

CWE-459 Incomplete Cleanup

Product status

Default status
unaffected

2.0.0 (semver)
affected

7.0.0 (semver)
affected

Credits

Nicolas Fournier reporter

References

cwiki.apache.org/confluence/display/WW/S2-068 vendor-advisory

cve.org/CVERecord?id=CVE-2025-64775 related

cve.org (CVE-2025-66675)

nvd.nist.gov (CVE-2025-66675)

Download JSON