Vulnerability Bulletins

CVE-2025-64775

   
Affected software APACHE
 
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion.

This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.0 through 7.0.3.

Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2025-64775