CVE-2025-64775

CVE-2025-64775: Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS)

Vendor Apache Software Foundation
Product Apache Struts
Weakness CWE-459
Published December 1, 2025
Last update December 1, 2025

CVSS base score

What the vulnerability does

Description

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.

Key dates

Disclosure timeline

December 1, 2025 CVE published
December 1, 2025 Record updated