Cyber Security News

Apache Struts 2 DoS Vulnerability Let Attackers Crash Server

A critical denial-of-service vulnerability has been discovered in Apache Struts 2, affecting multiple versions of the popular web application framework.

The vulnerability, identified as CVE-2025-64775, exploits a file leak in multipart request processing that can cause disk exhaustion and server crashes.

Organizations running affected versions should prioritize patching immediately to prevent potential service disruptions. The flaw exists in Apache Struts 2’s file upload functionality when enabled.

AttributeDetails
CVE IDCVE-2025-64775
ImpactDenial-of-Service
SeverityImportant
Fixed VersionsStruts 6.8.0+, Struts 7.1.1+
Patch StatusBackward Compatible

A file leak in multipart request processing causes disk exhaustion by allowing attackers to fill storage capacity without proper cleanup or resource management.

This results in a complete denial of service as the server becomes unable to process legitimate requests when disk space is exhausted.

Security researcher Nicolas Fournier discovered the vulnerability. This advisory is critical for all Apache Struts 2 developers, system administrators, and organizations deploying Struts-based applications.

Any organization with file upload capabilities enabled should immediately assess its environment and apply necessary patches.

Multiple versions across four major release lines are impacted.

VersionsStatusRecommendation
Struts 2.0.0 – 2.3.37EOL & VulnerableUpgrade immediately
Struts 2.5.0 – 2.5.33EOL & VulnerableUpgrade immediately
Struts 6.0.0 – 6.7.4VulnerableUpdate required
Struts 7.0.0 – 7.0.3VulnerableUpdate required
6.8.0+ or 7.1.1+SafeUse minimum recommended versions

Struts 2.0.0 through 2.3.37 are affected, though this version line reached end-of-life. Struts 2.5.0 through 2.5.33 are also vulnerable but similarly reached end-of-life status.

More critically, Struts 6.0.0 through 6.7.4 and Struts 7.0.0 through 7.0.3 remain actively maintained and require immediate updates. Organizations should upgrade to Struts 6.8.0 or Struts 7.1.1 at a minimum.

The patches are backward compatible, ensuring smooth transitions without breaking existing functionality.

Those unable to upgrade immediately can implement workarounds by configuring dedicated temporary folders with limited storage or by turning off file upload support if it is not required for operations.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago