GHSA-vv7r-c36w-3prj
GitHub Security Advisory
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.
This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4.
Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
Affected Packages
Maven
commons-fileupload:commons-fileupload
Affected versions:
1.0
(fixed in 1.6.0)
Maven
org.apache.commons:commons-fileupload2-core
Affected versions:
2.0.0-M1
(fixed in 2.0.0-M4)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 26, 2025 6:37 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.