CyberSec.Space Logo
Back to CVE Browser

CVE-2025-66675

HIGH
8.2
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-12-10
Last Modified2026-06-17
Data SourcesNVD

Vulnerability Description

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue. It's related to  https://cve.org/CVERecord?id=CVE-2025-64775  - this CVE addresses missing affected version 6.7.4

Affected Platforms (CPE)

📦
Apache

Struts

>= 2.0.0 and <= 2.3.37>= 2.5.0 and <= 2.5.33>= 6.0.0 and < 6.8.0>= 7.0.0 and < 7.1.1

References & Advisories

Related Vulnerabilities