PT-2025-25565 · Apache+10 · Apache Commons Fileupload+12

CVE-2025-48976

·

Published

2025-01-01

·

Updated

2026-06-17

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Commons FileUpload versions 1.0 through 1.5 Apache Commons FileUpload versions 2.0.0-M1 through 2.0.0-M3
Description The issue is related to the allocation of resources for multipart headers with insufficient limits, which enables a Denial of Service (DoS) vulnerability in Apache Commons FileUpload. A specially crafted request that uses a large number of parts with large headers could trigger excessive memory usage leading to a DoS. The limit for the size of the headers associated with a multipart request is now configurable with a default of 512 bytes.
Recommendations For Apache Commons FileUpload versions 1.0 through 1.5, upgrade to version 1.6. For Apache Commons FileUpload versions 2.0.0-M1 through 2.0.0-M3, upgrade to version 2.0.0-M4. As a temporary workaround, consider configuring the maxPartHeaderSize on the Connector to a suitable value to minimize the risk of exploitation.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:14177
ALSA-2025:14178
ALSA-2025:14181
ALT-PU-2025-13135
ALT-PU-2025-13307
BDU:2025-07776
CESA-2025_14177
CVE-2025-48976
DLA-4244-1
DLA-4245-1
GHSA-VV7R-C36W-3PRJ
INFSA-2025_14177
INFSA-2025_14181
MGASA-2025-0296
OESA-2025-1706
OESA-2025-1765
OESA-2025-1814
OESA-2025-1815
OESA-2025-1816
OESA-2025-1817
OESA-2025-1818
OESA-2025-1819
OPENSUSE-SU-2025:15208-1
RHSA-2025:11695
RHSA-2025:11741
RHSA-2025:14177
RHSA-2025:14178
RHSA-2025:14179
RHSA-2025:14180
RHSA-2025:14181
RHSA-2025:14182
RHSA-2025:14183
RHSA-2025_14177
RHSA-2025_14181
SUSE-SU-2025:02159-1
SUSE-SU-2025:02184-1
SUSE-SU-2025_02159-1
SUSE-SU-2025_02184-1

Affected Products

Alt Linux
Almalinux
Apache Commons Fileupload
Apache Tomcat
Astra Linux
Bamboo
Centos
Confluence
Debian
Red Hat
Red Os
Rocky Linux
Suse