VYPR

Commons Fileupload

by Apache

Source repositories

CVEs (7)

  • CVE-2016-1000031CriOct 25, 2016
    risk 0.66cvss 9.8epss 0.34

    Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution

  • CVE-2016-3092HigJul 4, 2016
    risk 0.52cvss 7.5epss 0.36

    The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long…

  • CVE-2026-71257HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.01

    Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons FileUpload. If the request body has already been consumed by another component, Commons FileUpload returns no items and Wicket falls back to…

  • CVE-2023-24998HigFeb 20, 2023
    risk 0.46cvss 7.5epss 0.49

    Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new…

  • CVE-2025-48976HigJun 16, 2025
    risk 0.44cvss 7.5epss 0.33

    Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6…

  • CVE-2014-0050Apr 1, 2014
    risk 0.03cvss —epss 0.83

    MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended…

  • CVE-2013-0248Mar 15, 2013
    risk 0.00cvss —epss 0.01

    The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.