← Back to browse · API

CVE-2025-48976

Severity
HIGH
CVSS
7.5
EPSS
0.67267
Risk score
53.54
CISA KEV
No
PoC
No
Published
2025-06-16
Modified
2025-11-03
First seen
2026-08-07
Aliases
EUVD-2025-18407, GHSA-VV7R-C36W-3PRJ
Products
Apache Software Foundation:Apache Commons FileUpload 1.0 <1.6, Apache Software Foundation:Apache Commons FileUpload 2.0.0-M1 <2.0.0-M4
Sources
euvd EUVD-2025-18407

Description

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.

References