Apache Struts Denial-of-Service Vulnerability Due to File Leak in Multipart Request Processing

Vulnerability

A denial-of-service vulnerability has been identified in Apache Struts versions 2.0.0 through 6.7.0 and 7.0.0 through 7.0.3. The issue arises from a file leak during multipart request processing, leading to disk exhaustion. Users are advised to upgrade to version 6.8.0 or 7.1.1, which address this vulnerability.

Impact

Exploitation of this vulnerability causes disk exhaustion, leading to a denial-of-service condition.

Remediation

Users should upgrade to Apache Struts version 6.8.0 or 7.1.1.

Added: Dec 1, 2025, 4:21 PM
Updated: Dec 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
2.5
exploitability
7.6
remediation
7.7
relevance
1.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.