CVE-2025-48976

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/06/2025
Last modified:
15/07/2025

Description

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.<br /> <br /> This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4.<br /> <br /> Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:commons_fileupload:*:*:*:*:*:*:*:* 1.0 (including) 1.6 (excluding)
cpe:2.3:a:apache:commons_fileupload:2.0.0:m1:*:*:*:*:*:*
cpe:2.3:a:apache:commons_fileupload:2.0.0:m1-rc1:*:*:*:*:*:*
cpe:2.3:a:apache:commons_fileupload:2.0.0:m2:*:*:*:*:*:*
cpe:2.3:a:apache:commons_fileupload:2.0.0:m2-rc1:*:*:*:*:*:*
cpe:2.3:a:apache:commons_fileupload:2.0.0:m3:*:*:*:*:*:*
cpe:2.3:a:apache:commons_fileupload:2.0.0:m3-rc1:*:*:*:*:*:*