cbcvebase.
CVE-2025-66675
published 2025-12-10

CVE-2025-66675: Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from…

PriorityP346high8.2CVSS 3.1
AVNACLPRNUINSUCLINAH
EPSS
0.52%
40.8th percentile
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue. It's related to https://cve.org/CVERecord?id=CVE-2025-64775 - this CVE addresses missing affected version 6.7.4

Affected

4 ranges
VendorProductVersion rangeFixed in
apachestruts2.0.0 – 2.3.37
apachestruts2.5.0 – 2.5.33
apachestruts>= 6.0.0 < 6.8.06.8.0
apachestruts>= 7.0.0 < 7.1.17.1.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.