https://seclists.org/oss-sec/2025/q4/257: CVE-2025-66675: Apache Struts: File leak in multipart quest processing causes disk exhaustion (DoS) - version ranges fixed
Published Dec 10, 2025
·Updated
Affected Software
2 affected components
Apache Struts>=2.0.0<6.7.5, >=7.0.0<7.0.4
maven/org.apache.struts/struts2-core>=2.0.0<6.7.5, >=7.0.0<7.0.4
Frequently Asked Questions
1
What is the severity of CVE-2025-66675?
The severity of CVE-2025-66675 is classified as important.
2
What versions of Apache Struts are affected by CVE-2025-66675?
CVE-2025-66675 affects Apache Struts versions 2.0.0 through 6.7.* and 7.0.0 through 7.0.*.
3
What kind of vulnerability is CVE-2025-66675?
CVE-2025-66675 is a Denial of Service vulnerability caused by a file leak in multipart request processing.
4
How do I fix CVE-2025-66675?
To fix CVE-2025-66675, upgrade to a version of Apache Struts that is not affected by this vulnerability.
5
When was CVE-2025-66675 published?
CVE-2025-66675 was published on December 10, 2025.