Re: [ANN] CVE-2025-64775: Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS) - S2-068

David Brunstein <[email protected]> Fri, 5 Dec 2025 01:30:26 -0600
Newsgroups gmane.comp.jakarta.struts.user
Message-ID <CAKxUg_XvUGRM=3suA2O3O4+hJaHiLL=vFV6SvZoQGDcP7j05UA@mail.gmail.com>
--000000000000f059e806452f6cb3
Content-Type: multipart/alternative; boundary="000000000000f059e706452f6cb2"

--000000000000f059e706452f6cb2
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi Lukasz,

Thank you for your confirmation.

S2-068
https://cwiki.apache.org/confluence/display/WW/S2-068

Under the Solution section, the page stands "Upgrade to Struts 6.8.0",
should it be updated to "Upgrade to Struts 6.7.0"?

[image: image.png]

Thanks,
Davo







On Fri, Dec 5, 2025 at 12:17=E2=80=AFAM =C5=81ukasz Lenart <lukasz.lenart@g=
mail.com>
wrote:

> I missed 6.7.4, sorry, my bad :( Any version above 6.7.x is fine.
>
> czw., 4 gru 2025 o 21:36 David Brunstein <[email protected]>
> napisa=C5=82(a):
> >
> > I am looking into CVE-2025-64775, and which Apache Struts2 versions are
> > affected.
> >
> > My findings on the web are inconsistent. Lukasz, can you confirm that
> this
> > would not affect versions of Struts 6 above Struts 6.7.0?
> >
> > Thank you,
> > Davo
> >
> > On Mon, Dec 1, 2025 at 8:45=E2=80=AFAM Lukasz Lenart <lukaszlenart@apac=
he.org>
> > wrote:
> >
> > > Severity: important
> > >
> > > Affected versions:
> > >
> > > - Apache Struts (org.apache.struts:struts2-core) 2.0.0 through 6.7.0
> > > - Apache Struts (org.apache.struts:struts2-core) 7.0.0 through 7.0.3
> > >
> > > Description:
> > >
> > > Denial of Service vulnerability in Apache Struts, file leak in
> > > multipart request processing causes disk exhaustion.
> > >
> > > This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.=
0
> > > through 7.0.3.
> > >
> > > Users are recommended to upgrade to version 6.8.0 or 7.1.1, which
> > > fixes the issue.
> > >
> > > Credit:
> > >
> > > Nicolas Fournier (reporter)
> > >
> > > References:
> > >
> > > https://cwiki.apache.org/confluence/display/WW/S2-068
> > > https://struts.apache.org/
> > > https://www.cve.org/CVERecord?id=3DCVE-2025-64775
> > >
> > >
> > > On behalf of the Apache Struts project
> > > =C5=81ukasz Lenart
> > >
> > > ---------------------------------------------------------------------
> > > To unsubscribe, e-mail: [email protected]
> > > For additional commands, e-mail: [email protected]
> > >
> > >
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>
>

--000000000000f059e706452f6cb2
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi Lukasz,<div><br></div><div>Thank you for your confirmat=
ion.</div><div><br></div><div>S2-068</div><div><a href=3D"https://cwiki.apa=
che.org/confluence/display/WW/S2-068">https://cwiki.apache.org/confluence/d=
isplay/WW/S2-068</a></div><div><br></div><div>Under the Solution section, t=
he page stands &quot;Upgrade to Struts 6.8.0&quot;, should it be updated to=
 &quot;Upgrade to Struts 6.7.0&quot;?<br><br><img src=3D"cid:ii_misjoc3n0" =
alt=3D"image.png" width=3D"504" height=3D"562"></div><div><br></div><div>Th=
anks,</div><div>Davo</div><div><br><br><br></div><div><br></div><div><br></=
div><div><br></div></div><br><div class=3D"gmail_quote gmail_quote_containe=
r"><div dir=3D"ltr" class=3D"gmail_attr">On Fri, Dec 5, 2025 at 12:17=E2=80=
=AFAM =C5=81ukasz Lenart &lt;<a href=3D"mailto:[email protected]">luk=
[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quo=
te" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204=
);padding-left:1ex">I missed 6.7.4, sorry, my bad :( Any version above 6.7.=
x is fine.<br>
<br>
czw., 4 gru 2025 o 21:36 David Brunstein &lt;<a href=3D"mailto:davidbrunste=
[email protected]" target=3D"_blank">[email protected]</a>&gt; napisa=C5=
=82(a):<br>
&gt;<br>
&gt; I am looking into CVE-2025-64775, and which Apache Struts2 versions ar=
e<br>
&gt; affected.<br>
&gt;<br>
&gt; My findings on the web are inconsistent. Lukasz, can you confirm that =
this<br>
&gt; would not affect versions of Struts 6 above Struts 6.7.0?<br>
&gt;<br>
&gt; Thank you,<br>
&gt; Davo<br>
&gt;<br>
&gt; On Mon, Dec 1, 2025 at 8:45=E2=80=AFAM Lukasz Lenart &lt;<a href=3D"ma=
ilto:[email protected]" target=3D"_blank">[email protected]</a>=
&gt;<br>
&gt; wrote:<br>
&gt;<br>
&gt; &gt; Severity: important<br>
&gt; &gt;<br>
&gt; &gt; Affected versions:<br>
&gt; &gt;<br>
&gt; &gt; - Apache Struts (org.apache.struts:struts2-core) 2.0.0 through 6.=
7.0<br>
&gt; &gt; - Apache Struts (org.apache.struts:struts2-core) 7.0.0 through 7.=
0.3<br>
&gt; &gt;<br>
&gt; &gt; Description:<br>
&gt; &gt;<br>
&gt; &gt; Denial of Service vulnerability in Apache Struts, file leak in<br=
>
&gt; &gt; multipart request processing causes disk exhaustion.<br>
&gt; &gt;<br>
&gt; &gt; This issue affects Apache Struts: from 2.0.0 through 6.7.0, from =
7.0.0<br>
&gt; &gt; through 7.0.3.<br>
&gt; &gt;<br>
&gt; &gt; Users are recommended to upgrade to version 6.8.0 or 7.1.1, which=
<br>
&gt; &gt; fixes the issue.<br>
&gt; &gt;<br>
&gt; &gt; Credit:<br>
&gt; &gt;<br>
&gt; &gt; Nicolas Fournier (reporter)<br>
&gt; &gt;<br>
&gt; &gt; References:<br>
&gt; &gt;<br>
&gt; &gt; <a href=3D"https://cwiki.apache.org/confluence/display/WW/S2-068"=
 rel=3D"noreferrer" target=3D"_blank">https://cwiki.apache.org/confluence/d=
isplay/WW/S2-068</a><br>
&gt; &gt; <a href=3D"https://struts.apache.org/" rel=3D"noreferrer" target=
=3D"_blank">https://struts.apache.org/</a><br>
&gt; &gt; <a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-64775" rel=
=3D"noreferrer" target=3D"_blank">https://www.cve.org/CVERecord?id=3DCVE-20=
25-64775</a><br>
&gt; &gt;<br>
&gt; &gt;<br>
&gt; &gt; On behalf of the Apache Struts project<br>
&gt; &gt; =C5=81ukasz Lenart<br>
&gt; &gt;<br>
&gt; &gt; -----------------------------------------------------------------=
----<br>
&gt; &gt; To unsubscribe, e-mail: <a href=3D"mailto:user-unsubscribe@struts=
.apache.org" target=3D"_blank">[email protected]</a><br>
&gt; &gt; For additional commands, e-mail: <a href=3D"mailto:user-help@stru=
ts.apache.org" target=3D"_blank">[email protected]</a><br>
&gt; &gt;<br>
&gt; &gt;<br>
<br>
---------------------------------------------------------------------<br>
To unsubscribe, e-mail: <a href=3D"mailto:[email protected]=
g" target=3D"_blank">[email protected]</a><br>
For additional commands, e-mail: <a href=3D"mailto:[email protected].=
org" target=3D"_blank">[email protected]</a><br>
<br>
</blockquote></div>

--000000000000f059e706452f6cb2--
--000000000000f059e806452f6cb3--