CVE-2025-48976

Aliases:GHSA-vv7r-c36w-3prjUBUNTU-CVE-2025-48976DEBIAN-CVE-2025-48976CGA-327g-3hfp-v785CGA-4j57-g89m-qvgjCGA-56vr-jcgm-xvfcCGA-5q99-m8f7-j326CGA-873q-f8f7-87xjCGA-8hvw-gxp6-4ph5CGA-8mr5-v32j-7rh7CGA-9gr9-9gh8-c3cfCGA-f477-p76w-h48xCGA-hhw8-wp3j-gq8pCGA-hjfg-7hhx-j8jxCGA-2gh6-crf7-2grpCGA-6g4x-mq96-v8mgCGA-7w27-cmgh-ph3fCGA-8rq8-vr6c-9hcqCGA-ccqx-fwv2-53xpCGA-fmq7-58v2-xq23CGA-fwwf-g689-hc26CGA-j6rg-vcqv-ppmxCGA-mqh6-5xfh-3g49CGA-q6xq-vfff-crxxCGA-r974-3vvp-2xm3CGA-vf5j-2v6g-jjqwCGA-wjx2-qgfj-c22p
Advisory lineage Upstream: 0 Downstream: 19
Modified
Published: 16 Jun 2025, 15:00
Last modified:03 Nov 2025, 20:05

Vulnerability Summary

Overall Risk (default)
medium
37/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
32.96% HIGH
33% probability +32.77%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Jun 2025, 15:00
Published
Vulnerability first disclosed
03 Nov 2025, 20:05
Last Modified
Vulnerability information updated

Description

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.

CVSS Metrics

  • v4.0HIGHScore: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 32.96% Percentile: 98%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • apache software foundationapache commons fileupload

    ≥ 1.0, < 1.6 | ≥ 2.0.0-M1, < 2.0.0-M4

  • apachecommons_fileupload

    ≥ 1.0, < 1.6 | 2.0.0:m1 | 2.0.0:m1-rc1 | 2.0.0:m2 | 2.0.0:m2-rc1 | 2.0.0:m3 | 2.0.0:m3-rc1

  • chainguardgeoserver-2.27

    < 2.27.1-r1

  • chainguardgeoserver-2.27-community

    < 2.27.1-r1

  • chainguardgeoserver-2.27-docker

    < 2.27.1-r1

  • chainguardjenkins-2

    < 2.515-r0

  • chainguardjenkins-2-openjdk-17

    < 2.515-r0

  • chainguardjenkins-2-openjdk-21

    < 2.515-r0

  • chainguardjenkins-2.504-openjdk-17

    all

  • chainguardjenkins-2.504-openjdk-21

    all

  • chainguardjenkins-compat

    < 2.515-r0

  • chainguardjenkins-docker-agent-openjdk-21

    < 2.515-r0

  • chainguardjenkins-remoting

    < 2.515-r0

  • chainguardjenkins-utils

    < 2.515-r0

  • wolfijenkins-2

    < 2.515-r0

  • wolfijenkins-2-openjdk-17

    < 2.515-r0

  • wolfijenkins-2-openjdk-21

    < 2.515-r0

  • wolfijenkins-compat

    < 2.515-r0

  • wolfijenkins-docker-agent-openjdk-21

    < 2.515-r0

  • wolfijenkins-remoting

    < 2.515-r0

  • wolfijenkins-utils

    < 2.515-r0

  • debianlibcommons-fileupload-java

    < 1.4-1+deb11u1 | all | all | all

  • debiantomcat10

    < 10.1.52-1~deb12u1 | < 10.1.52-1~deb13u1 | < 10.1.46-1

  • debiantomcat11

    < 11.0.15-1~deb13u1 | < 11.0.11-1

  • debiantomcat9

    < 9.0.107-0+deb11u1 | < 9.0.70-2 | < 9.0.70-2 | < 9.0.70-2

  • ubuntulibcommons-fileupload-java

    all | all | all | all | all | all | all

  • ubuntutomcat10

    all | all | all

  • ubuntutomcat11

    all | all

  • ubuntutomcat6

    all

  • ubuntutomcat9

    all

  • commons-fileuploadcommons-fileupload

    ≥ 1.0, < 1.6.0

  • org.apache.commonscommons-fileupload2-core

    ≥ 2.0.0-M1, < 2.0.0-M4

References (17)