This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.0 through 7.0.3.
Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xx7v-hqxh-cjr9 | Apache Struts is Vulnerable to DoS via File Leak |
Wed, 03 Dec 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* |
Tue, 02 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 01 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache struts |
|
| Vendors & Products |
Apache
Apache struts |
Mon, 01 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 01 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 01 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue. | |
| Title | Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS) | |
| Weaknesses | CWE-459 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-12-01T18:23:17.469Z
Reserved: 2025-11-11T15:12:23.069Z
Link: CVE-2025-64775
Updated: 2025-12-01T17:05:44.577Z
Status : Analyzed
Published: 2025-12-01T16:15:56.873
Modified: 2026-01-26T11:30:04.700
Link: CVE-2025-64775
OpenCVE Enrichment
Updated: 2025-12-01T21:27:31Z
Github GHSA