CVE-2025-64775

Publication date 1 December 2025

Last updated 3 December 2025


Ubuntu priority

Description

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue.

Status

Package Ubuntu Release Status


Access our resources on patching vulnerabilities