8.2
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Description
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion.
This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3.
Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.
It's related toΒ https://cve.org/CVERecord?id=CVE-2025-64775 Β - this CVE addresses missing affected version 6.7.4
This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3.
Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.
It's related toΒ https://cve.org/CVERecord?id=CVE-2025-64775 Β - this CVE addresses missing affected version 6.7.4
Basic Information
ID
CVE-2025-66675
Source
apache
Published
Dec 10, 2025 at 09:32
Modified
Dec 10, 2025 at 14:53
Affected Product
Vendor
Apache Software Foundation
Product
Apache Struts
Version
2.0.0
Affected Versions
Apache Software Foundation Apache Struts 2.0.0
Apache Software Foundation Apache Struts 7.0.0
Apache Software Foundation Apache Struts 7.0.0