Summary

File leak in multipart request processing causes disk exhaustion (DoS)


Who should read this

All Struts 2 developers and users

Impact of vulnerability

Denial of service

Maximum security rating

Important

Recommendation

Upgrade to Struts 6.9.0 at least or 7.1.0

Affected Software

  • Struts 2.0.0 through Struts 2.3.37 (EOL)
  • Struts 2.5.0 through Struts 2.5.33 (EOL)
  • Struts 6.0.0 through Struts 6.7.0
  • Struts 7.0.0 through Struts 7.0.3

Reporters

Nicolas Fournier

CVE Identifier

CVE-2025-64775

Problem

File leak in multipart request processing causes disk exhaustion.

Solution

Upgrade to Struts 6.8.0 (or to the latest version of 6.x) or upgrade to Struts 7.1.0 at least.

Backward compatibility

This change is backward compatible.

Workaround

n/a