Apache Product Security Update Advisory (CVE-2025-64775)
Overview
We have released security updates to fix vulnerabilities in Apache products. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2025-64775
Apache Struts version: 2.0.0. or earlier and 6.7.0 or earlier
Apache Struts version: 7.0.0. or later and 7.0.3 or earlier
Resolved Vulnerabilities
Denial of service vulnerability due to temporary file accumulation in Apache Struts (CVE-2025-64775)
Vulnerability Patches
Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2025-64775
Apache Struts Version: 6.8.0
Apache Struts Version: 7.1.1
References
[1] Mozilla Foundation Security Advisory 2025-47
https://www.openwall.com/lists/oss-security/2025/12/01/2