Apache Struts is a widely used open-source framework for building modern web applications in Java. Its prevalence in enterprise environments and public-facing websites makes it a critical component of Internet infrastructure and a high-value target for attackers.
This vulnerability represents a high risk, allowing an unauthenticated remote attacker to cause a Denial of Service (DoS) condition. The impact consists of disk space exhaustion, which can render the web application, and potentially the entire underlying server, unresponsive. This leads to business operation disruptions, negatively impacts the user experience, and can cause financial losses.
Although there are currently no confirmed reports of active exploitation in real-world environments, a public exploit is available. This significantly increases the likelihood of opportunistic or targeted attacks against vulnerable systems. Any server exposed to the Internet running a vulnerable version of Apache Struts should be considered at immediate risk.
| Product | Apache Struts |
| Date | 2025-12-03 16:47:36 |
Technical Summary
The root cause of this vulnerability is improper resource cleanup within the Apache Struts multipart request processing component. When a user submits data, such as a file, via a multipart request, the framework creates temporary files on the server’s disk to handle the data. The vulnerability lies in the failure to correctly delete these temporary files once the request has been processed.
The attack chain is as follows:
- An attacker sends a series of specially crafted multipart requests to an endpoint of an application based on a vulnerable version of Apache Struts.
- The framework’s multipart request parser processes each request, creating a temporary file on the disk for each one.
- Due to the flaw, the framework does not execute the necessary cleanup logic, leaving orphaned temporary files on the file system.
- By repeating this process, an attacker can progressively fill the available disk space, eventually causing complete exhaustion. This leads to a Denial of Service, as the application and other system processes are no longer able to write to the disk.
This issue affects Apache Struts versions from 2.0.0 to 6.7.0 and from 7.0.0 to 7.0.3. The vulnerability has been fixed in versions 6.7.1, 7.0.4, and later. An unauthenticated attacker can exploit this vulnerability to deny service without the need for special privileges.
Recommendations
- Update immediately: Upgrade all Apache Struts instances to the latest secure versions, such as 6.7.1 or 7.0.4, which include the fix for the vulnerability.
- Mitigations: If applying the patch immediately is not possible, consider implementing rate-limiting on endpoints that handle multipart/form-data requests to slow down file creation. You can configure Web Application Firewalls (WAFs) to block malformed multipart requests, although this does not replace the update.
- Threat Hunting and Monitoring:
- Closely monitor disk space usage on servers running Apache Struts applications for any rapid and unexplained increases.
- Inspect the temporary file directory used by the Java application server (e.g., the
tempdirectory in Apache Tomcat) to ensure there are no anomalous files that are not being removed.
- Incident Response: In case of suspected compromise, immediately proceed to delete orphaned temporary files from the disk to restore service. Isolate the compromised host and analyze the web server access logs for repeated POST requests originating from a single IP address. Retain logs for forensic analysis before applying the necessary patch.
- Defense in Depth: Ensure that the web service runs with a low-privileged user account, equipped with quotas that limit the ability to exhaust system-level disk space. This can help confine the impact of the DoS to the application itself rather than the entire server. Perform regular backups of critical data and configurations.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
