CVE-2025-48976

Source
https://cve.org/CVERecord?id=CVE-2025-48976
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-48976.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-48976
Aliases
Downstream
CGA (24)
CLSA (4)
DEBIAN (1)
ECHO (1)
MGASA (1)
MINI (4)
OESA (8)
openSUSE (1)
RHSA (9)
RLSA (4)
ROOT (1)
SUSE (2)
UBUNTU (1)
Related
Published
2025-06-16T15:00:48Z
Modified
2026-08-12T03:51:36Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
Details

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.

This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4.

Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.

Database specific
{
    "cna_assigner":  "apache",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/48xxx/CVE-2025-48976.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "1.0"
                },
                {
                    "fixed":  "1.6"
                },
                {
                    "introduced":  "2.0.0-M1"
                },
                {
                    "fixed":  "2.0.0-M4"
                }
            ],
            "source":  "AFFECTED_FIELD"
        },
        {
            "extracted_events":  [
                {
                    "introduced":  "1.0"
                },
                {
                    "fixed":  "1.6"
                },
                {
                    "introduced":  "2.0.0-M1"
                },
                {
                    "fixed":  "2.0.0-M4"
                }
            ],
            "source":  "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/apache/commons-fileupload

Affected ranges

Type
GIT
Repo
https://github.com/apache/commons-fileupload
Events
Database specific
Show details
{
    "cpe":  [
        "cpe:2.3:a:apache:commons_fileupload:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:commons_fileupload:2.0.0:m1:*:*:*:*:*:*",
        "cpe:2.3:a:apache:commons_fileupload:2.0.0:m1-rc1:*:*:*:*:*:*",
        "cpe:2.3:a:apache:commons_fileupload:2.0.0:m2:*:*:*:*:*:*",
        "cpe:2.3:a:apache:commons_fileupload:2.0.0:m2-rc1:*:*:*:*:*:*",
        "cpe:2.3:a:apache:commons_fileupload:2.0.0:m3:*:*:*:*:*:*",
        "cpe:2.3:a:apache:commons_fileupload:2.0.0:m3-rc1:*:*:*:*:*:*"
    ],
    "extracted_events":  [
        {
            "introduced":  "1.0"
        },
        {
            "fixed":  "1.6"
        },
        {
            "introduced":  "2.0.0-m1"
        },
        {
            "last_affected":  "2.0.0-m1"
        },
        {
            "introduced":  "2.0.0-m1\\-rc1"
        },
        {
            "last_affected":  "2.0.0-m1\\-rc1"
        },
        {
            "introduced":  "2.0.0-m2"
        },
        {
            "last_affected":  "2.0.0-m2"
        },
        {
            "introduced":  "2.0.0-m2\\-rc1"
        },
        {
            "last_affected":  "2.0.0-m2\\-rc1"
        },
        {
            "introduced":  "2.0.0-m3"
        },
        {
            "last_affected":  "2.0.0-m3"
        },
        {
            "introduced":  "2.0.0-m3\\-rc1"
        },
        {
            "last_affected":  "2.0.0-m3\\-rc1"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "CPE_STRING"
    ]
}

Affected versions

2.*
2.0.0-m1
2.0.0-m2
2.0.0-m3
2.0.0-m3\-rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-48976.json"