{"id":9150,"date":"2025-12-12T10:04:09","date_gmt":"2025-12-12T10:04:09","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/12\/apache-struts-2-dos-vulnerability-let-attackers-crash-server\/"},"modified":"2025-12-12T10:04:09","modified_gmt":"2025-12-12T10:04:09","slug":"apache-struts-2-dos-vulnerability-let-attackers-crash-server","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/12\/apache-struts-2-dos-vulnerability-let-attackers-crash-server\/","title":{"rendered":"Apache Struts 2 DoS Vulnerability Let Attackers Crash Server"},"content":{"rendered":"<p>    Apache Struts 2 DoS Vulnerability Let Attackers Crash Server<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p id=\"h-\">A critical denial-of-service vulnerability has been discovered in Apache Struts 2, affecting multiple versions of the popular web application framework.<\/p>\n<p>The vulnerability, identified as CVE-2025-64775, exploits a file leak in multipart request processing that can cause <a href=\"https:\/\/cybersecuritynews.com\/apache-struts-vulnerability-disk-exhaustion-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">disk exhaustion<\/a> and server crashes.<\/p>\n<p>Organizations running affected versions should prioritize patching immediately to prevent potential service disruptions. The flaw exists in Apache Struts 2\u2019s file upload functionality when enabled.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\"><strong>Attribute<\/strong><\/th>\n<th class=\"has-text-align-left\" data-align=\"left\"><strong>Details<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>CVE ID<\/strong><\/td>\n<td>CVE-2025-64775<\/td>\n<\/tr>\n<tr>\n<td><strong>Impact<\/strong><\/td>\n<td><a href=\"https:\/\/cybersecuritynews.com\/denial-of-servicedos-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">Denial-of-Service<\/a><\/td>\n<\/tr>\n<tr>\n<td><strong>Severity<\/strong><\/td>\n<td>Important<\/td>\n<\/tr>\n<tr>\n<td><strong>Fixed Versions<\/strong><\/td>\n<td>Struts 6.8.0+, Struts 7.1.1+<\/td>\n<\/tr>\n<tr>\n<td><strong>Patch Status<\/strong><\/td>\n<td>Backward Compatible<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>A <a href=\"https:\/\/cybersecuritynews.com\/accenture-files\/\" target=\"_blank\" rel=\"noreferrer noopener\">file leak<\/a> in multipart request processing causes disk exhaustion by allowing attackers to fill storage capacity without proper cleanup or resource management.<\/p>\n<p>This results in a complete denial of service as the server becomes unable to process legitimate requests when disk space is exhausted.<\/p>\n<p>Security researcher Nicolas Fournier <a href=\"https:\/\/cwiki.apache.org\/confluence\/display\/WW\/S2-068\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">discovered<\/a> the vulnerability. This advisory is critical for all Apache Struts 2 developers, system administrators, and organizations deploying Struts-based applications.<\/p>\n<p>Any organization with file upload capabilities enabled should immediately assess its environment and apply necessary patches.<\/p>\n<p>Multiple versions across four major release lines are impacted.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Versions<\/th>\n<th>Status<\/th>\n<th>Recommendation<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Struts 2.0.0 \u2013 2.3.37<\/strong><\/td>\n<td>EOL &amp; Vulnerable<\/td>\n<td>Upgrade immediately<\/td>\n<\/tr>\n<tr>\n<td><strong>Struts 2.5.0 \u2013 2.5.33<\/strong><\/td>\n<td>EOL &amp; Vulnerable<\/td>\n<td>Upgrade immediately<\/td>\n<\/tr>\n<tr>\n<td><strong>Struts 6.0.0 \u2013 6.7.4<\/strong><\/td>\n<td>Vulnerable<\/td>\n<td>Update required<\/td>\n<\/tr>\n<tr>\n<td><strong>Struts 7.0.0 \u2013 7.0.3<\/strong><\/td>\n<td>Vulnerable<\/td>\n<td>Update required<\/td>\n<\/tr>\n<tr>\n<td><strong>6.8.0+ or 7.1.1+<\/strong><\/td>\n<td>Safe<\/td>\n<td>Use minimum recommended versions<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Struts 2.0.0 through 2.3.37 are affected, though this version line reached <a href=\"https:\/\/cybersecuritynews.com\/secure-data-center-decommissioning-end-of-life-isnt-end-of-risk\/\" target=\"_blank\" rel=\"noreferrer noopener\">end-of-life<\/a>. Struts 2.5.0 through 2.5.33 are also vulnerable but similarly reached end-of-life status.<\/p>\n<p>More critically, Struts 6.0.0 through 6.7.4 and Struts 7.0.0 through 7.0.3 remain actively maintained and require immediate updates. Organizations should upgrade to Struts 6.8.0 or Struts 7.1.1 at a minimum.<\/p>\n<p>The patches are backward compatible, ensuring smooth transitions without breaking existing functionality.<\/p>\n<p id=\"h-\">Those unable to upgrade immediately can implement workarounds by configuring dedicated temporary folders with limited storage or by turning off file upload support if it is not required for operations.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/apache-struts-2-dos-vulnerability\/\">Apache Struts 2 DoS Vulnerability Let Attackers Crash Server<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/apache-struts-2-dos-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apache Struts 2 DoS Vulnerability Let Attackers Crash Server A critical denial-of-service vulnerability has been discovered in Apache Struts 2, affecting multiple versions of the popular web application framework. The vulnerability, identified as CVE-2025-64775, exploits a file leak in multipart request processing that can cause disk exhaustion and server crashes. Organizations running affected versions should [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-9150","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9150"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9150"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9150\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9150"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9150"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9150"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}