cbcvebase.
CVE-2025-64775
published 2025-12-01

CVE-2025-64775: Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.

Affected

7 ranges
VendorProductVersion rangeFixed in
apachestruts>= 2.0.0 < 6.8.06.8.0
apachestruts2.0.0 – 2.3.37
apachestruts2.5.0 – 2.5.33
apachestruts>= 6.0.0 < 6.8.06.8.0
apachestruts>= 7.0.0 < 7.1.17.1.1
apache_software_foundationapache_struts2.0.0 – 6.7.*
apache_software_foundationapache_struts7.0.0 – 7.0.*