CVE-2025-48976
published 2025-06-16CVE-2025-48976: Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache…
PriorityP261high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
67.27%
99.2th percentile
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.
This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4.
Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | commons_fileupload | — | — |
| apache | commons_fileupload | >= 1.0 < 1.6 | 1.6 |
| apache_software_foundation | apache_commons_fileupload | >= 1.0 < 1.6 | 1.6 |
| apache_software_foundation | apache_commons_fileupload | >= 2.0.0-M1 < 2.0.0-M4 | 2.0.0-M4 |
| debian | libcommons-fileupload-java | < libcommons-fileupload-java 1.4-1+deb11u1 (bullseye) | libcommons-fileupload-java 1.4-1+deb11u1 (bullseye) |
| debian | tomcat10 | < libcommons-fileupload-java 1.4-1+deb11u1 (bullseye) | libcommons-fileupload-java 1.4-1+deb11u1 (bullseye) |
| debian | tomcat11 | < libcommons-fileupload-java 1.4-1+deb11u1 (bullseye) | libcommons-fileupload-java 1.4-1+deb11u1 (bullseye) |
| debian | tomcat9 | < libcommons-fileupload-java 1.4-1+deb11u1 (bullseye) | libcommons-fileupload-java 1.4-1+deb11u1 (bullseye) |
| msrc | cbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered by sending a specially crafted HTTP multipart request with an excessively large number of multipart headers, causing uncontrolled memory consumption (DoS) in applications using Apache Commons FileUpload. ↗
- →Monitor for abnormally large or numerous multipart headers in HTTP POST requests to endpoints that use Apache Commons FileUpload (versions 1.0–1.5.x or 2.0.0-M1–2.0.0-M3); alert on requests with header counts or sizes exceeding normal thresholds. ↗
- →CWE-770 (Allocation of Resources Without Limits or Throttling) — detection should focus on resource exhaustion patterns (memory spikes, OOM events) correlated with multipart HTTP upload requests. ↗
- ·Affected versions span two release lines: 1.0 through 1.5.x (fix in 1.6) and 2.0.0-M1 through 2.0.0-M3 (fix in 2.0.0-M4). Ensure version checks cover both branches. ↗
- ·Siemens Industrial Edge Management OS (IEM-OS) — ALL versions are affected with no patched firmware release; recommended workaround is migration to IEM-V and restricting network access to trusted users/systems only. ↗
- ·Numerous Red Hat products have fixes deferred (not yet available), including commons-fileupload packages across A-MQ, Camel, JBoss EAP 7/8, Data Grid, Debezium, Fuse, OpenShift Dev Spaces, Satellite, and others — treat these as unpatched in affected environments. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-48976: Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload
osv·2025-06-16·CVSS 7.5
CVE-2025-48976 [HIGH] CVE-2025-48976: Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
OSV
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
osv·2025-06-16
CVE-2025-48976 [HIGH] Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.
This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4.
Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
GHSA
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
ghsa·2025-06-16
CVE-2025-48976 [HIGH] CWE-770 Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.
This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4.
Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
Oracle
Oracle Oracle Communications Risk Matrix: Third Party (Apache Commons FileUpload) — CVE-2025-48976
vendor_oracle·2026-01-15·CVSS 7.5
CVE-2025-48976 [HIGH] Oracle Oracle Communications Risk Matrix: Third Party (Apache Commons FileUpload) — CVE-2025-48976
Oracle Oracle Communications Risk Matrix: Third Party (Apache Commons FileUpload) vulnerability
CVE: CVE-2025-48976
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Oracle
Oracle Oracle GoldenGate Risk Matrix: General (Apache Commons FileUpload) — CVE-2025-48976
vendor_oracle·2025-10-15·CVSS 6.5
CVE-2025-48976 [HIGH] Oracle Oracle GoldenGate Risk Matrix: General (Apache Commons FileUpload) — CVE-2025-48976
Oracle Oracle GoldenGate Risk Matrix: General (Apache Commons FileUpload) vulnerability
CVE: CVE-2025-48976
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
CISA ICS
Siemens Industrial Edge Management OS (IEM-OS)
cisa_ics·2025-09-11·CVSS 7.5
[HIGH] Siemens Industrial Edge Management OS (IEM-OS)
ICS Advisory
##
Siemens Industrial Edge Management OS (IEM-OS)
Release DateSeptember 11, 2025
Alert CodeICSA-25-254-06
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Industrial Edge Management OS (IEM-OS)
- Vulnerability: Allocation of Resources Without Limits or Throttling
Red Hat
apache-commons-fileupload: Apache Commons FileUpload DoS via part headers
vendor_redhat·2025-06-16·CVSS 7.5
CVE-2025-48976 [HIGH] CWE-770 apache-commons-fileupload: Apache Commons FileUpload DoS via part headers
apache-commons-fileupload: Apache Commons FileUpload DoS via part headers
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.
This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4.
Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
A denial-of-service (DoS) vulnerability has been discovered in the Apache Commons FileUpload library. The flaw stems from insufficient limits placed on multipart headers during file uploads. A remote attacker could exploit this by sending a specially crafted request with an excessively large number of multipart headers. This malicious input can lead to uncontrolled memory consumption within applications utilizi
Debian
CVE-2025-48976: libcommons-fileupload-java - Allocation of resources for multipart headers with insufficient limits enabled a...
vendor_debian·2025·CVSS 7.5
CVE-2025-48976 [HIGH] CVE-2025-48976: libcommons-fileupload-java - Allocation of resources for multipart headers with insufficient limits enabled a...
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1.4-1+deb11u1)
forky: open
sid: open
trixie: open
Microsoft
netfilter: flowtable_offload: fix using __this_cpu_add in preemptible
vendor_msrc·2024-10-08·CVSS 5.5
CVE-2022-48976 [MEDIUM] netfilter: flowtable_offload: fix using __this_cpu_add in preemptible
netfilter: flowtable_offload: fix using __this_cpu_add in preemptible
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-48976 tomcat: Apache Commons FileUpload DoS via part headers [fedora-42]
bugzilla·2026-01-15·CVSS 7.5
CVE-2025-48976 [HIGH] CVE-2025-48976 tomcat: Apache Commons FileUpload DoS via part headers [fedora-42]
CVE-2025-48976 tomcat: Apache Commons FileUpload DoS via part headers [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-48976 tomcat: Apache Commons FileUpload DoS via part headers [fedora-41]
bugzilla·2026-01-15·CVSS 7.5
CVE-2025-48976 [HIGH] CVE-2025-48976 tomcat: Apache Commons FileUpload DoS via part headers [fedora-41]
CVE-2025-48976 tomcat: Apache Commons FileUpload DoS via part headers [fedora-41]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
F41 reached EOL.
Bugzilla
CVE-2025-48976 apache-commons-fileupload: Apache Commons FileUpload DoS via part headers
bugzilla·2025-06-16·CVSS 7.5
CVE-2025-48976 [HIGH] CVE-2025-48976 apache-commons-fileupload: Apache Commons FileUpload DoS via part headers
CVE-2025-48976 apache-commons-fileupload: Apache Commons FileUpload DoS via part headers
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.
This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4.
Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Web Server 5.8 on RHEL 7
Red Hat JBoss Web Server 5.8 on RHEL 8
Red Hat JBoss Web Server 5.8 on RHEL 9
Via RHSA-2025:11695 https://access.redhat.com/errata/RHSA-2025:11695
---
This issue has been addressed in the following products:
Red Hat JBoss Web Server 5.8.5
Via RHSA-2025:11696 https://access.redhat.c
2025-06-16
Published