ThreatCluster

Critical DoS Vulnerability Found in Apache Struts 2 Framework

First seen 12 Dec 2025, 10:51 UTC Cybersecuritynews 30

Article Content

Browse articles
ThreatCluster

A critical denial-of-service vulnerability, CVE-2025-64775, has been identified in Apache Struts 2, impacting multiple versions of the web application framework. This vulnerability exploits a file leak in multipart request processing, leading to potential disk exhaustion and server crashes. Organizations using affected versions are urged to prioritize patching to avoid service disruptions.