Skip to main content

Vendor/product archive

apache / commons_fileupload CVEs

Beta · best-effort

6 CVEs tagged to apache / commons_fileupload1 Critical, 4 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2025-48976

Published Jun 16, 2025

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: fro…

CVSS 7.5 · High
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2023-24998

Published Feb 20, 2023

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious uploa…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2016-1000031

Published Oct 25, 2016

Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2013-0248

Published Mar 15, 2013

The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to o…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1