File leak in multipart request processing causes disk exhaustion (DoS) |
Who should read this | All Struts 2 developers and users |
|---|---|
Impact of vulnerability | Denial of service |
Maximum security rating | Important |
Recommendation | Upgrade to Struts 6.8.0 at least or 7.1.1 |
Affected Software | |
Reporters | Nicolas Fournier |
CVE Identifier | CVE-2025-64775 |
File leak in multipart request processing causes disk exhaustion.
Upgrade to Struts 6.8.0 or upgrade to Struts 7.1.1 at least.
This change is backward compatible.
n/a