This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4.
Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4244-1 | tomcat9 security update |
Debian DLA |
DLA-4245-1 | libcommons-fileupload-java security update |
EUVD |
EUVD-2025-18407 | Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue. |
Github GHSA |
GHSA-vv7r-c36w-3prj | Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 15 Jul 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:commons_fileupload:2.0.0:rc1:*:*:*:*:*:* |
cpe:2.3:a:apache:commons_fileupload:2.0.0:m1:*:*:*:*:*:* |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs |
Wed, 02 Jul 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache commons Fileupload |
|
| CPEs | cpe:2.3:a:apache:commons_fileupload:*:*:*:*:*:*:*:* cpe:2.3:a:apache:commons_fileupload:2.0.0:m1-rc1:*:*:*:*:*:* cpe:2.3:a:apache:commons_fileupload:2.0.0:m2-rc1:*:*:*:*:*:* cpe:2.3:a:apache:commons_fileupload:2.0.0:m2:*:*:*:*:*:* cpe:2.3:a:apache:commons_fileupload:2.0.0:m3-rc1:*:*:*:*:*:* cpe:2.3:a:apache:commons_fileupload:2.0.0:m3:*:*:*:*:*:* cpe:2.3:a:apache:commons_fileupload:2.0.0:m4-rc1:*:*:*:*:*:* cpe:2.3:a:apache:commons_fileupload:2.0.0:m4:*:*:*:*:*:* cpe:2.3:a:apache:commons_fileupload:2.0.0:rc1:*:*:*:*:*:* |
|
| Vendors & Products |
Apache
Apache commons Fileupload |
Tue, 17 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Tue, 17 Jun 2025 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 16 Jun 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 16 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue. | |
| Title | Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-11-03T20:05:02.486Z
Reserved: 2025-05-29T07:19:14.431Z
Link: CVE-2025-48976
Updated: 2025-11-03T20:05:02.486Z
Status : Modified
Published: 2025-06-16T15:15:24.460
Modified: 2025-11-03T20:19:07.730
Link: CVE-2025-48976
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA