#VU118877 Resource exhaustion in Apache Struts - CVE-2025-64775
Published: December 1, 2025 / Updated: December 4, 2025
Apache Struts
Apache Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling multipart requests. A remote attacker can consume all disk space on the system and perform a denial of service (DoS) attack.