Apache Commons FileUpload Denial-of-Service Vulnerability via Multipart Headers

Vulnerability

A denial-of-service vulnerability has been identified in Apache Commons FileUpload versions 1.0 prior to 1.6 and 2.0.0-M1 prior to 2.0.0-M4. The issue arises from the allocation of resources for multipart headers without adequate limits, allowing for potential resource exhaustion.

Impact

Exploitation of this vulnerability can lead to a denial-of-service condition, causing the application to become unresponsive or unavailable.

Remediation

Users are advised to upgrade to Apache Commons FileUpload version 1.6 or 2.0.0-M4, both of which address this vulnerability.

Added: Jun 16, 2025, 3:26 PM
Updated: Jun 16, 2025, 3:26 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
2.5
exploitability
4.7
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.