CVE-2025-66675
EUVD-2025-20241710.12.2025, 10:16
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue. It's related to https://cve.org/CVERecord?id=CVE-2025-64775 - this CVE addresses missing affected version 6.7.4Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | struts | 2.0.0 ≤ 𝑥 ≤ 2.3.37 |
| apache | struts | 2.5.0 ≤ 𝑥 ≤ 2.5.33 |
| apache | struts | 6.0.0 ≤ 𝑥 < 6.8.0 |
| apache | struts | 7.0.0 ≤ 𝑥 < 7.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration