High Severity Vulnerability
This vulnerability has been rated as High severity. Immediate action is recommended.
CVE-2025-48976
HighVulnerability Description
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.
This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4.
Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Known Affected Software
13 configuration(s) from 1 vendor(s)
cpe:2.3:a:apache:commons_fileupload:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_fileupload:1.5:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_fileupload:1.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_fileupload:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_fileupload:1.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_fileupload:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_fileupload:1.4:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_fileupload:1.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_fileupload:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_fileupload:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_fileupload:2.0.0:m1:*:*:*:*:*:*
cpe:2.3:a:apache:commons_fileupload:1.0:beta:*:*:*:*:*:*
cpe:2.3:a:apache:commons_fileupload:1.3.3:*:*:*:*:*:*:*
CPUAPR2026
Oracle Critical Patch Update Advisory - April 2026
CPUJAN2026
Oracle Critical Patch Update Advisory - January 2026
CPUOCT2025
Oracle Critical Patch Update Advisory - October 2025
CPUJUL2025
Oracle Critical Patch Update Advisory - July 2025
CVE-2025-48976
CVE-2025-48976
References & Resources
-
https://lists.apache.org/thread/fbs3wrr3p67vkjcxogqqqqz45pqtso12security@apache.org Mailing List Vendor Advisory
-
http://www.openwall.com/lists/oss-security/2025/06/16/4af854a3a-2127-422b-91ae-364da2661108 Mailing List Third Party Advisory
-
https://lists.debian.org/debian-lts-announce/2025/07/msg00008.htmlaf854a3a-2127-422b-91ae-364da2661108
-
https://lists.debian.org/debian-lts-announce/2025/07/msg00009.htmlaf854a3a-2127-422b-91ae-364da2661108
Severity Details
Weakness Type (CWE)
Allocation of Resources Without Limits or Throttling
- Description
- The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
- Exploit Likelihood
- High
- Typical Severity
- Medium
- Abstraction Level
- Base
Key Information
- Published Date
- June 16, 2025
