7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion.
This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.0 through 7.0.3.
Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.
This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.0 through 7.0.3.
Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.
Basic Information
ID
CVE-2025-64775
Source
apache
Published
Dec 1, 2025 at 16:07
Modified
Dec 1, 2025 at 18:23
Affected Product
Vendor
Apache Software Foundation
Product
Apache Struts
Version
2.0.0
Affected Versions
Apache Software Foundation Apache Struts 2.0.0
Apache Software Foundation Apache Struts 7.0.0
Apache Software Foundation Apache Struts 7.0.0