VendorsApachecommons_fileuploadany version
Vulnerabilities

Apache Commons Fileupload any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2016-1000031
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
Published 2016-10-25 · Modified
9.8EPSS 0.337
CVE-2016-3092
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
Published 2016-07-04 · Modified
7.8EPSS 0.359
CVE-2014-0050
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
Published 2014-03-28 · Modified
7.51 PoCEPSS 0.832
CVE-2023-24998
Apache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive parts
Published 2023-02-20 · Modified
7.5EPSS 0.488
CVE-2025-48976
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
Published 2025-06-16 · Modified
7.5EPSS 0.330