CVE-2025-48976
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
- Affected products
- Alt Linux, Almalinux, Apache Commons Fileupload, Apache Tomcat, Astra Linux, Bamboo, Centos, Confluence
- Apache Commons Fileupload
- < 1.6, 2.0.0
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 67.3% (99th percentile)
- Weakness
- CWE-770
- NVD status
- Modified
- Published
- 2025-06-16
CVE-2025-48976 at NVD
1 known exploit for CVE-2025-48976
Proof-of-concept code and exploit modules indexed by Sploitus