CVE-2025-48976
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
Description
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
In plain language
AI Worth attentionApache Commons FileUpload versions before 1.6, and FileUpload 2.0.0-M1 through 2.0.0-M3, can be crashed by oversized upload metadata, so small businesses using it should schedule an update soon.
Unauthenticated network DoS caused by insufficient resource limits when parsing multipart part headers (CWE-770).
What to do now
- Ask IT to check whether any application uses Apache Commons FileUpload and identify its installed version.
- Upgrade the 1.x package to 1.6.0 or later.
- Upgrade the 2.x core package to 2.0.0-M4 or later.
- Until updated, restrict public file-upload endpoints and enforce request-size limits at the web server or gateway.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-48976 and every CVE in our database. Create a free account — no credit card required.
Create Free Account