{"id":"CVE-2025-48976","details":"Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.\n\nThis issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4.\n\nUsers are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.","aliases":["GHSA-vv7r-c36w-3prj"],"modified":"2026-04-16T04:37:30.939824792Z","published":"2025-06-16T15:15:24.460Z","related":["ALSA-2025:14177","ALSA-2025:14178","ALSA-2025:14181","CGA-jwxx-8jj7-h645","SUSE-SU-2025:02159-1","SUSE-SU-2025:02184-1","openSUSE-SU-2025:15208-1"],"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/07/msg00008.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/fbs3wrr3p67vkjcxogqqqqz45pqtso12"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2025/06/16/4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/commons-fileupload","events":[{"introduced":"cdfbeaa120cba6a8f1527b91600317ee374450c2"},{"fixed":"f3e030f09ac8b01b684466c793dec86eafe1e4c9"},{"introduced":"0"},{"last_affected":"2107cd3dbb58417ccf1afae055aac3d5f597a665"},{"introduced":"0"},{"last_affected":"2107cd3dbb58417ccf1afae055aac3d5f597a665"},{"introduced":"0"},{"last_affected":"bcb3e82c164f8b9998b22e58e32463f634eaca8d"},{"introduced":"0"},{"last_affected":"bcb3e82c164f8b9998b22e58e32463f634eaca8d"},{"introduced":"0"},{"last_affected":"a49c1757bc16940d65f2f5bf30c27956e6b6869a"},{"introduced":"0"},{"last_affected":"a75dde28fe9e340a2f89c349f05a4ee5281417be"}],"database_specific":{"versions":[{"introduced":"1.0"},{"fixed":"1.6"},{"introduced":"0"},{"last_affected":"2.0.0-m1"},{"introduced":"0"},{"last_affected":"2.0.0-m1\\-rc1"},{"introduced":"0"},{"last_affected":"2.0.0-m2"},{"introduced":"0"},{"last_affected":"2.0.0-m2\\-rc1"},{"introduced":"0"},{"last_affected":"2.0.0-m3"},{"introduced":"0"},{"last_affected":"2.0.0-m3\\-rc1"}]}}],"versions":["commons-fileupload-1.4","commons-fileupload-1.4-RC1","commons-fileupload-1.4-RC2","commons-fileupload-1.5","commons-fileupload-1.5-RC1","commons-fileupload-2.0.0-M1-RC1","commons-fileupload-2.0.0-M2-RC1","commons-fileupload-2.0.0-M3-RC1","rel/commons-fileupload-2.0.0-M1","rel/commons-fileupload-2.0.0-M2","rel/commons-fileupload-2.0.0-M3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-48976.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}