Description

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.

INFO

Published Date :

2025-12-01T16:07:36.573Z

Last Modified :

2025-12-01T18:23:17.469Z

Source :

apache
AFFECTED PRODUCTS

The following products are affected by CVE-2025-64775 vulnerability.

Vendors Products
Apache
  • Struts

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact