File leak in multipart request processing causes disk exhaustion (DoS) |
Who should read this | All Struts 2 developers and users |
|---|---|
Impact of vulnerability | Denial of service |
Maximum security rating | Important |
Recommendation | Upgrade to Struts 6.9.0 at least or 7.1.0 |
Affected Software | |
Reporters | Nicolas Fournier |
CVE Identifier | CVE-2025-64775 |
File leak in multipart request processing causes disk exhaustion.
Upgrade to Struts 6.8.0 (or to the latest version of 6.x) or upgrade to Struts 7.1.0 at least.
This change is backward compatible.
n/a