cbcvebase.
CVE-2025-64775
published 2025-12-01

CVE-2025-64775: Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from…

PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.46%
70.6th percentile
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.

Affected

7 ranges
VendorProductVersion rangeFixed in
apachestruts>= 2.0.0 < 6.8.06.8.0
apachestruts2.0.0 – 2.3.37
apachestruts2.5.0 – 2.5.33
apachestruts>= 6.0.0 < 6.8.06.8.0
apachestruts>= 7.0.0 < 7.1.17.1.1
apache_software_foundationapache_struts2.0.0 – 6.7.*
apache_software_foundationapache_struts7.0.0 – 7.0.*

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.