cbcvebase.
CVE-2025-48976
published 2025-06-16

CVE-2025-48976: Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache…

PriorityP261high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
67.27%
99.2th percentile
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.

Affected

11 ranges
VendorProductVersion rangeFixed in
apachecommons_fileupload
apachecommons_fileupload>= 1.0 < 1.61.6
apache_software_foundationapache_commons_fileupload>= 1.0 < 1.61.6
apache_software_foundationapache_commons_fileupload>= 2.0.0-M1 < 2.0.0-M42.0.0-M4
debianlibcommons-fileupload-java< libcommons-fileupload-java 1.4-1+deb11u1 (bullseye)libcommons-fileupload-java 1.4-1+deb11u1 (bullseye)
debiantomcat10< libcommons-fileupload-java 1.4-1+deb11u1 (bullseye)libcommons-fileupload-java 1.4-1+deb11u1 (bullseye)
debiantomcat11< libcommons-fileupload-java 1.4-1+deb11u1 (bullseye)libcommons-fileupload-java 1.4-1+deb11u1 (bullseye)
debiantomcat9< libcommons-fileupload-java 1.4-1+deb11u1 (bullseye)libcommons-fileupload-java 1.4-1+deb11u1 (bullseye)
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered by sending a specially crafted HTTP multipart request with an excessively large number of multipart headers, causing uncontrolled memory consumption (DoS) in applications using Apache Commons FileUpload.
  • Monitor for abnormally large or numerous multipart headers in HTTP POST requests to endpoints that use Apache Commons FileUpload (versions 1.0–1.5.x or 2.0.0-M1–2.0.0-M3); alert on requests with header counts or sizes exceeding normal thresholds.
  • CWE-770 (Allocation of Resources Without Limits or Throttling) — detection should focus on resource exhaustion patterns (memory spikes, OOM events) correlated with multipart HTTP upload requests.
  • ·Affected versions span two release lines: 1.0 through 1.5.x (fix in 1.6) and 2.0.0-M1 through 2.0.0-M3 (fix in 2.0.0-M4). Ensure version checks cover both branches.
  • ·Siemens Industrial Edge Management OS (IEM-OS) — ALL versions are affected with no patched firmware release; recommended workaround is migration to IEM-V and restricting network access to trusted users/systems only.
  • ·Numerous Red Hat products have fixes deferred (not yet available), including commons-fileupload packages across A-MQ, Camel, JBoss EAP 7/8, Data Grid, Debezium, Fuse, OpenShift Dev Spaces, Satellite, and others — treat these as unpatched in affected environments.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.