DNA View

High Severity Vulnerability

This vulnerability has been rated as High severity. Immediate action is recommended.

CVE-2025-48976

High
Low Medium High Critical
7.5
CVSS Score
Published: Jun 16, 2025
Last Modified: Nov 03, 2025

Vulnerability Description

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.

This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4.

Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
N
Attack Complexity
L
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
N
Integrity
N
Availability
H

Known Affected Software

13 configuration(s) from 1 vendor(s)

commons_fileupload
Version:
1.2.1
CPE:
cpe:2.3:a:apache:commons_fileupload:1.2.1:*:*:*:*:*:*:*
commons_fileupload
Version:
1.5
CPE:
cpe:2.3:a:apache:commons_fileupload:1.5:*:*:*:*:*:*:*
commons_fileupload
Version:
1.3
CPE:
cpe:2.3:a:apache:commons_fileupload:1.3:*:*:*:*:*:*:*
commons_fileupload
Version:
1.3.1
CPE:
cpe:2.3:a:apache:commons_fileupload:1.3.1:*:*:*:*:*:*:*
commons_fileupload
Version:
1.1
CPE:
cpe:2.3:a:apache:commons_fileupload:1.1:*:*:*:*:*:*:*
commons_fileupload
Version:
1.1.1
CPE:
cpe:2.3:a:apache:commons_fileupload:1.1.1:*:*:*:*:*:*:*
commons_fileupload
Version:
1.4
CPE:
cpe:2.3:a:apache:commons_fileupload:1.4:*:*:*:*:*:*:*
commons_fileupload
Version:
1.2
CPE:
cpe:2.3:a:apache:commons_fileupload:1.2:*:*:*:*:*:*:*
commons_fileupload
Version:
1.2.2
CPE:
cpe:2.3:a:apache:commons_fileupload:1.2.2:*:*:*:*:*:*:*
commons_fileupload
Version:
1.3.2
CPE:
cpe:2.3:a:apache:commons_fileupload:1.3.2:*:*:*:*:*:*:*
commons_fileupload
Version:
2.0.0
CPE:
cpe:2.3:a:apache:commons_fileupload:2.0.0:m1:*:*:*:*:*:*
commons_fileupload
Version:
1.0
CPE:
cpe:2.3:a:apache:commons_fileupload:1.0:beta:*:*:*:*:*:*
commons_fileupload
Version:
1.3.3
CPE:
cpe:2.3:a:apache:commons_fileupload:1.3.3:*:*:*:*:*:*:*
This vulnerability affects 13 software configuration(s). Ensure you patch all affected systems.

Available Security Patches

5 patches available from vendors

View All Patches
Oracle

CPUAPR2026

Oracle Critical Patch Update Advisory - April 2026

Severity
Critical
Released
Apr 21, 2026
Restart Required
Security Update
Oracle

CPUJAN2026

Oracle Critical Patch Update Advisory - January 2026

Severity
Critical
Released
Jan 20, 2026
Restart Required
Security Update
Oracle

CPUOCT2025

Oracle Critical Patch Update Advisory - October 2025

Severity
Critical
Released
Oct 21, 2025
Restart Required
Security Update
Oracle

CPUJUL2025

Oracle Critical Patch Update Advisory - July 2025

Severity
Critical
Released
Jul 15, 2025
Restart Required
Security Update
SUSE

CVE-2025-48976

CVE-2025-48976

Severity
Unknown
Released
Jun 16, 2025
Security Update

Severity Details

7.5
out of 10.0
High

Weakness Type (CWE)

CWE-770

Allocation of Resources Without Limits or Throttling

Description
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Exploit Likelihood
High
Typical Severity
Medium
Abstraction Level
Base

Key Information

Published Date
June 16, 2025