Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.
This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4.
Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade tomcat-el-3.0-apiUpgrade tomcat-admin-webappsUpgrade tomcat-docs-webappUpgrade tomcatUpgrade tomcat-webappsUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-libUpgrade tomcat-servlet-4.0-api | Aug 22, 2025 | Aug 20, 2025 |
| Amazon Linux Ami 2 | — | Upgrade tomcat-admin-webappsUpgrade tomcat-webappsUpgrade tomcat-servlet-3.0-apiUpgrade tomcat-javadocUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-jsp-2.2-apiUpgrade tomcat-el-2.2-apiUpgrade tomcat-libUpgrade tomcat-el-3.0-apiUpgrade tomcatUpgrade tomcat-docs-webappUpgrade tomcat-jsvc | May 20, 2026 | May 20, 2026 |
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 9.0.106Upgrade Apache Tomcat to 10.1.42Upgrade Apache Tomcat to 11.0.8 | Jun 17, 2025 | Jun 16, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 16, 2025 |
| Atlassian Jira | — | Upgrade to the latest version of Atlassian JIRA | Dec 11, 2025 | Nov 18, 2025 |
| Debian | — | Upgrade tomcat10Upgrade tomcat11Upgrade tomcat9Upgrade libcommons-fileupload-java | Jun 18, 2025 | Jun 16, 2025 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jul 17, 2025 |
| Ibm Was | — | Upgrade to version 25.0.0.9.Upgrade to version 8.5.5.29.Upgrade to minimal fix pack levels as required by interim fixes and then apply Interim Fix PH67137.Upgrade to version 9.0.5.26.Upgrade to minimal fix pack levels as required by interim fixes and then apply Interim Fix PH67132. | Aug 13, 2025 | Aug 13, 2025 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 38793419 for version 14.1.1.0.0.Apply the Patch Set Update (PSU) 38792523 for version 12.2.1.4.0. | Jan 23, 2026 | Jun 16, 2025 |
| Oracle_linux | — | Upgrade tomcat9Upgrade tomcat-admin-webappsUpgrade tomcat9-jsp-2.3-apiUpgrade tomcat9-webappsUpgrade tomcat-libUpgrade tomcat-servlet-6.0-apiUpgrade tomcatUpgrade tomcat9-el-3.0-apiUpgrade tomcat-jsp-3.1-apiUpgrade tomcat-el-5.0-apiUpgrade tomcat9-docs-webappUpgrade tomcat-docs-webappUpgrade tomcat9-servlet-4.0-apiUpgrade tomcat-jsp-2.3-apiUpgrade tomcat9-admin-webappsUpgrade tomcat-servlet-4.0-apiUpgrade tomcat9-libUpgrade tomcat-el-3.0-apiUpgrade tomcat-webapps | Aug 21, 2025 | Jun 16, 2025 |
| Red Hat Jboss Eap | — | — | Jun 17, 2025 | Jun 16, 2025 |
| Redhat_linux | — | Upgrade tomcatUpgrade tomcat-jsp-3.1-apiUpgrade tomcat9-webappsUpgrade jws6-tomcat-selinuxUpgrade tomcat9-docs-webappUpgrade jws6-tomcat-jsp-3.1-apiUpgrade tomcat-el-3.0-apiUpgrade tomcat9-servlet-4.0-apiUpgrade jws6-tomcat-admin-webappsUpgrade tomcat-servlet-6.0-apiUpgrade tomcat-libUpgrade tomcat-el-5.0-apiUpgrade jws6-tomcat-libUpgrade jws6-tomcat-el-5.0-apiUpgrade tomcat-docs-webappUpgrade jws6-tomcatUpgrade tomcat9Upgrade tomcat9-jsp-2.3-apiUpgrade tomcat-jsp-2.3-apiNo solution existsUpgrade tomcat-webappsUpgrade tomcat-servlet-4.0-apiUpgrade tomcat9-libUpgrade jws6-tomcat-docs-webappUpgrade tomcat-admin-webappsUpgrade jws6-tomcat-webappsUpgrade jws6-tomcat-servlet-6.0-apiUpgrade tomcat9-admin-webappsUpgrade jws6-tomcat-javadocUpgrade tomcat9-el-3.0-api | Jul 9, 2025 | Jun 16, 2025 |
| Suse | — | Upgrade jakarta-commons-fileuploadUpgrade apache-commons-fileuploadUpgrade apache-commons-fileupload-javadocUpgrade jakarta-commons-fileupload-javadoc | Dec 5, 2025 | Aug 27, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub