CVE-2025-48976

CVE-2025-48976: Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers

Vendor Apache Software Foundation
Product Apache Commons FileUpload
Published June 16, 2025
Last update November 3, 2025

CVSS base score

What the vulnerability does

Description

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.

Key dates

Disclosure timeline

June 16, 2025 CVE published
November 3, 2025 Record updated