CVE-2025-48976

Severity
7.5HIGH
EPSS
1.3%
top 20.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 16
Latest updateJan 15

Description

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages8 packages

🔴Vulnerability Details

4
OSV
CVE-2025-48976: Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload2025-06-16
CVEList
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers2025-06-16
OSV
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers2025-06-16
GHSA
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers2025-06-16

📋Vendor Advisories

5
Oracle
Oracle Oracle Communications Risk Matrix: Third Party (Apache Commons FileUpload) — CVE-2025-489762026-01-15
Oracle
Oracle Oracle GoldenGate Risk Matrix: General (Apache Commons FileUpload) — CVE-2025-489762025-10-15
Red Hat
apache-commons-fileupload: Apache Commons FileUpload DoS via part headers2025-06-16
Debian
CVE-2025-48976: libcommons-fileupload-java - Allocation of resources for multipart headers with insufficient limits enabled a...2025
Microsoft
netfilter: flowtable_offload: fix using __this_cpu_add in preemptible2024-10-08

💬Community

2
Bugzilla
CVE-2025-48976 tomcat: Apache Commons FileUpload DoS via part headers [fedora-42]2026-01-15
Bugzilla
CVE-2025-48976 tomcat: Apache Commons FileUpload DoS via part headers [fedora-41]2026-01-15
CVE-2025-48976 (HIGH CVSS 7.5) | Allocation of resources for multipa | cvebase.io