CVE-2025-66675: Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS) - version ranges fixed
Published Dec 10, 2025
·Updated
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion.
This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3.
Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.
Affected Software
7 affected componentsFixes available
Apache Struts>=2.0.0<=6.7.4, >=7.0.0<=7.0.3
maven/org.apache.struts:struts2-core>=7.0.0<7.1.1
7.1.1
maven/org.apache.struts:struts2-core>=2.0.0<6.8.0
6.8.0
Apache Struts>=2.0.0<=2.3.37
Apache Struts>=2.5.0<=2.5.33
Apache Struts>=6.0.0<6.8.0
Apache Struts>=7.0.0<7.1.1
Event History
Dec 10, 2025
CVE Published
via MITRE·09:32 AM
Data Sourced
via MITRE·09:32 AM
DescriptionWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·12:31 PM
Data Sourced
via GitHub·12:31 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-66675?
CVE-2025-66675 is classified as a Denial of Service vulnerability.
2
How do I fix CVE-2025-66675?
To fix CVE-2025-66675, upgrade Apache Struts to version 6.8.0 or 7.1.1.
3
Which versions of Apache Struts are affected by CVE-2025-66675?
CVE-2025-66675 affects Apache Struts versions from 2.0.0 through 6.7.4 and 7.0.0 through 7.0.3.
4
What type of issue does CVE-2025-66675 cause?
CVE-2025-66675 causes disk exhaustion due to a file leak in multipart request processing.
5
Is there a workaround for CVE-2025-66675?
The recommended action for CVE-2025-66675 is to upgrade to a secure version, as no specific workaround is provided.