[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2025-48976":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":406,"aliases":407,"duplicate_of":9,"upstream":409,"downstream":410,"duplicates":449,"related":450,"reserved_at":9,"published_at":459,"modified_at":460,"state":461,"summary":462,"references_raw":471,"kevs":516,"epss":517,"epss_history":520,"metrics":806,"affected":818},"CVE-2025-48976","Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.\n\nThis issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4.\n\nUsers are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-770","Allocation of Resources Without Limits or Throttling","The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.","weakness","Incomplete","Base","High",[20,106,116,120,124,128,132,136,168,230,234,238,268,298,330,334,338,342,346,350],{"id":21,"name":22,"techniques":23},"CAPEC-125","Flooding",[24,78],{"id":25,"name":26,"tactics":27,"countermeasures":31},"T1498.001","Direct Network Flood",[28],{"id":29,"name":30},"TA0105","Impact",[32,37,41,45,49,53,57,61,65,69,74],{"id":33,"name":34,"tactic":35},"D3-UGLPA","User Geolocation Logon Pattern Analysis",{"name":36},"Detect",{"id":38,"name":39,"tactic":40},"D3-PMAD","Protocol Metadata Anomaly Detection",{"name":36},{"id":42,"name":43,"tactic":44},"D3-CSPP","Client-server Payload Profiling",{"name":36},{"id":46,"name":47,"tactic":48},"D3-PHDURA","Per Host Download-Upload Ratio Analysis",{"name":36},{"id":50,"name":51,"tactic":52},"D3-NTSA","Network Traffic Signature Analysis",{"name":36},{"id":54,"name":55,"tactic":56},"D3-APCA","Application Protocol Command Analysis",{"name":36},{"id":58,"name":59,"tactic":60},"D3-NTCD","Network Traffic Community Deviation",{"name":36},{"id":62,"name":63,"tactic":64},"D3-RTSD","Remote Terminal Session Detection",{"name":36},{"id":66,"name":67,"tactic":68},"D3-ISVA","Inbound Session Volume Analysis",{"name":36},{"id":70,"name":71,"tactic":72},"D3-NTF","Network Traffic Filtering",{"name":73},"Isolate",{"id":75,"name":76,"tactic":77},"D3-ITF","Inbound Traffic Filtering",{"name":73},{"id":79,"name":80,"tactics":81,"countermeasures":83},"T1499","Endpoint Denial of Service",[82],{"id":29,"name":30},[84,86,88,90,92,94,96,98,100,102,104],{"id":33,"name":34,"tactic":85},{"name":36},{"id":38,"name":39,"tactic":87},{"name":36},{"id":42,"name":43,"tactic":89},{"name":36},{"id":46,"name":47,"tactic":91},{"name":36},{"id":50,"name":51,"tactic":93},{"name":36},{"id":54,"name":55,"tactic":95},{"name":36},{"id":58,"name":59,"tactic":97},{"name":36},{"id":62,"name":63,"tactic":99},{"name":36},{"id":66,"name":67,"tactic":101},{"name":36},{"id":70,"name":71,"tactic":103},{"name":73},{"id":75,"name":76,"tactic":105},{"name":73},{"id":107,"name":108,"techniques":109},"CAPEC-130","Excessive Allocation",[110],{"id":111,"name":112,"tactics":113,"countermeasures":115},"T1499.003","Application Exhaustion Flood",[114],{"id":29,"name":30},[],{"id":117,"name":118,"techniques":119},"CAPEC-147","XML Ping of the Death",[],{"id":121,"name":122,"techniques":123},"CAPEC-197","Exponential Data Expansion",[],{"id":125,"name":126,"techniques":127},"CAPEC-229","Serialized Data Parameter Blowup",[],{"id":129,"name":130,"techniques":131},"CAPEC-230","Serialized Data with Nested Payloads",[],{"id":133,"name":134,"techniques":135},"CAPEC-231","Oversized Serialized Data Payloads",[],{"id":137,"name":138,"techniques":139},"CAPEC-469","HTTP DoS",[140],{"id":141,"name":142,"tactics":143,"countermeasures":145},"T1499.002","Service Exhaustion Flood",[144],{"id":29,"name":30},[146,148,150,152,154,156,158,160,162,164,166],{"id":33,"name":34,"tactic":147},{"name":36},{"id":38,"name":39,"tactic":149},{"name":36},{"id":42,"name":43,"tactic":151},{"name":36},{"id":46,"name":47,"tactic":153},{"name":36},{"id":50,"name":51,"tactic":155},{"name":36},{"id":54,"name":55,"tactic":157},{"name":36},{"id":58,"name":59,"tactic":159},{"name":36},{"id":62,"name":63,"tactic":161},{"name":36},{"id":66,"name":67,"tactic":163},{"name":36},{"id":70,"name":71,"tactic":165},{"name":73},{"id":75,"name":76,"tactic":167},{"name":73},{"id":169,"name":170,"techniques":171},"CAPEC-482","TCP Flood",[172,198,204],{"id":25,"name":26,"tactics":173,"countermeasures":175},[174],{"id":29,"name":30},[176,178,180,182,184,186,188,190,192,194,196],{"id":33,"name":34,"tactic":177},{"name":36},{"id":38,"name":39,"tactic":179},{"name":36},{"id":42,"name":43,"tactic":181},{"name":36},{"id":46,"name":47,"tactic":183},{"name":36},{"id":50,"name":51,"tactic":185},{"name":36},{"id":54,"name":55,"tactic":187},{"name":36},{"id":58,"name":59,"tactic":189},{"name":36},{"id":62,"name":63,"tactic":191},{"name":36},{"id":66,"name":67,"tactic":193},{"name":36},{"id":70,"name":71,"tactic":195},{"name":73},{"id":75,"name":76,"tactic":197},{"name":73},{"id":199,"name":200,"tactics":201,"countermeasures":203},"T1499.001","OS Exhaustion Flood",[202],{"id":29,"name":30},[],{"id":141,"name":142,"tactics":205,"countermeasures":207},[206],{"id":29,"name":30},[208,210,212,214,216,218,220,222,224,226,228],{"id":33,"name":34,"tactic":209},{"name":36},{"id":38,"name":39,"tactic":211},{"name":36},{"id":42,"name":43,"tactic":213},{"name":36},{"id":46,"name":47,"tactic":215},{"name":36},{"id":50,"name":51,"tactic":217},{"name":36},{"id":54,"name":55,"tactic":219},{"name":36},{"id":58,"name":59,"tactic":221},{"name":36},{"id":62,"name":63,"tactic":223},{"name":36},{"id":66,"name":67,"tactic":225},{"name":36},{"id":70,"name":71,"tactic":227},{"name":73},{"id":75,"name":76,"tactic":229},{"name":73},{"id":231,"name":232,"techniques":233},"CAPEC-486","UDP Flood",[],{"id":235,"name":236,"techniques":237},"CAPEC-487","ICMP Flood",[],{"id":239,"name":240,"techniques":241},"CAPEC-488","HTTP Flood",[242],{"id":141,"name":142,"tactics":243,"countermeasures":245},[244],{"id":29,"name":30},[246,248,250,252,254,256,258,260,262,264,266],{"id":33,"name":34,"tactic":247},{"name":36},{"id":38,"name":39,"tactic":249},{"name":36},{"id":42,"name":43,"tactic":251},{"name":36},{"id":46,"name":47,"tactic":253},{"name":36},{"id":50,"name":51,"tactic":255},{"name":36},{"id":54,"name":55,"tactic":257},{"name":36},{"id":58,"name":59,"tactic":259},{"name":36},{"id":62,"name":63,"tactic":261},{"name":36},{"id":66,"name":67,"tactic":263},{"name":36},{"id":70,"name":71,"tactic":265},{"name":73},{"id":75,"name":76,"tactic":267},{"name":73},{"id":269,"name":270,"techniques":271},"CAPEC-489","SSL Flood",[272],{"id":141,"name":142,"tactics":273,"countermeasures":275},[274],{"id":29,"name":30},[276,278,280,282,284,286,288,290,292,294,296],{"id":33,"name":34,"tactic":277},{"name":36},{"id":38,"name":39,"tactic":279},{"name":36},{"id":42,"name":43,"tactic":281},{"name":36},{"id":46,"name":47,"tactic":283},{"name":36},{"id":50,"name":51,"tactic":285},{"name":36},{"id":54,"name":55,"tactic":287},{"name":36},{"id":58,"name":59,"tactic":289},{"name":36},{"id":62,"name":63,"tactic":291},{"name":36},{"id":66,"name":67,"tactic":293},{"name":36},{"id":70,"name":71,"tactic":295},{"name":73},{"id":75,"name":76,"tactic":297},{"name":73},{"id":299,"name":300,"techniques":301},"CAPEC-490","Amplification",[302],{"id":303,"name":304,"tactics":305,"countermeasures":307},"T1498.002","Reflection Amplification",[306],{"id":29,"name":30},[308,310,312,314,316,318,320,322,324,326,328],{"id":33,"name":34,"tactic":309},{"name":36},{"id":38,"name":39,"tactic":311},{"name":36},{"id":42,"name":43,"tactic":313},{"name":36},{"id":46,"name":47,"tactic":315},{"name":36},{"id":50,"name":51,"tactic":317},{"name":36},{"id":54,"name":55,"tactic":319},{"name":36},{"id":58,"name":59,"tactic":321},{"name":36},{"id":62,"name":63,"tactic":323},{"name":36},{"id":66,"name":67,"tactic":325},{"name":36},{"id":70,"name":71,"tactic":327},{"name":73},{"id":75,"name":76,"tactic":329},{"name":73},{"id":331,"name":332,"techniques":333},"CAPEC-491","Quadratic Data Expansion",[],{"id":335,"name":336,"techniques":337},"CAPEC-493","SOAP Array Blowup",[],{"id":339,"name":340,"techniques":341},"CAPEC-494","TCP Fragmentation",[],{"id":343,"name":344,"techniques":345},"CAPEC-495","UDP Fragmentation",[],{"id":347,"name":348,"techniques":349},"CAPEC-496","ICMP Fragmentation",[],{"id":351,"name":352,"techniques":353},"CAPEC-528","XML Flood",[354,380],{"id":141,"name":142,"tactics":355,"countermeasures":357},[356],{"id":29,"name":30},[358,360,362,364,366,368,370,372,374,376,378],{"id":33,"name":34,"tactic":359},{"name":36},{"id":38,"name":39,"tactic":361},{"name":36},{"id":42,"name":43,"tactic":363},{"name":36},{"id":46,"name":47,"tactic":365},{"name":36},{"id":50,"name":51,"tactic":367},{"name":36},{"id":54,"name":55,"tactic":369},{"name":36},{"id":58,"name":59,"tactic":371},{"name":36},{"id":62,"name":63,"tactic":373},{"name":36},{"id":66,"name":67,"tactic":375},{"name":36},{"id":70,"name":71,"tactic":377},{"name":73},{"id":75,"name":76,"tactic":379},{"name":73},{"id":25,"name":26,"tactics":381,"countermeasures":383},[382],{"id":29,"name":30},[384,386,388,390,392,394,396,398,400,402,404],{"id":33,"name":34,"tactic":385},{"name":36},{"id":38,"name":39,"tactic":387},{"name":36},{"id":42,"name":43,"tactic":389},{"name":36},{"id":46,"name":47,"tactic":391},{"name":36},{"id":50,"name":51,"tactic":393},{"name":36},{"id":54,"name":55,"tactic":395},{"name":36},{"id":58,"name":59,"tactic":397},{"name":36},{"id":62,"name":63,"tactic":399},{"name":36},{"id":66,"name":67,"tactic":401},{"name":36},{"id":70,"name":71,"tactic":403},{"name":73},{"id":75,"name":76,"tactic":405},{"name":73},[],[408],"GHSA-vv7r-c36w-3prj",[],[411,413,415,417,419,421,423,425,427,429,431,433,435,437,439,441,443,445,447],{"_key":412},"SUSE-SU-2025:02159-1",{"_key":414},"DLA-4244-1",{"_key":416},"DLA-4245-1",{"_key":418},"DSA-6120-1",{"_key":420},"DSA-6121-1",{"_key":422},"SUSE-SU-2025:02184-1",{"_key":424},"OPENSUSE-SU-2025:15208-1",{"_key":426},"MGASA-2025-0296",{"_key":428},"DEBIAN-CVE-2025-48976",{"_key":430},"RHSA-2025:11695",{"_key":432},"RHSA-2025:11741",{"_key":434},"RHSA-2025:14177",{"_key":436},"RHSA-2025:14178",{"_key":438},"RHSA-2025:14179",{"_key":440},"RHSA-2025:14180",{"_key":442},"RHSA-2025:14181",{"_key":444},"RHSA-2025:14182",{"_key":446},"RHSA-2025:14183",{"_key":448},"UBUNTU-CVE-2025-48976",[],[451,452,453,454,455,457],{"_key":412},{"_key":422},{"_key":424},{"_key":426},{"_key":456},"CGA-XMRQ-2G6W-RJ66",{"_key":458},"CGA-JWXX-8JJ7-H645","2025-06-16T15:00:48.140Z","2025-11-03T20:05:02.486Z","Modified",{"cisa_kev":463,"cisa_ransomware":463,"cisa_vendor":9,"epss_severity":464,"epss_score":465,"severity":466,"severity_score":467,"severity_version":468,"severity_source":469,"severity_vector":470,"severity_status":461},false,"low",0.01278,"high",7.5,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",[472,481,486,490,494,499,503,507,511],{"url":473,"sources":474,"tags":477},"https://lists.apache.org/thread/fbs3wrr3p67vkjcxogqqqqz45pqtso12",[469,475,476],"nvd","osv_maven",[478,479,480],"Vendor Advisory","Mailing List","WEB",{"url":482,"sources":483,"tags":484},"http://www.openwall.com/lists/oss-security/2025/06/16/4",[469,475,476],[479,485,480],"Third Party Advisory",{"url":487,"sources":488,"tags":489},"https://lists.debian.org/debian-lts-announce/2025/07/msg00008.html",[469,475,476],[480],{"url":491,"sources":492,"tags":493},"https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html",[469,475,476],[480],{"url":495,"sources":496,"tags":497},"https://nvd.nist.gov/vuln/detail/CVE-2025-48976",[476],[498],"Advisory",{"url":500,"sources":501,"tags":502},"https://github.com/apache/commons-fileupload/commit/b247774a72a044f5d5380ae947140ee80af4e78b",[476],[480],{"url":504,"sources":505,"tags":506},"https://github.com/apache/commons-fileupload/commit/bf68f63cfb312ef4710fb3dfb4d8e4e1665f4497",[476],[480],{"url":508,"sources":509,"tags":510},"https://github.com/apache/tomcat/commit/97790a35a27d236fa053e660676c3f8196284d93",[476],[480],{"url":512,"sources":513,"tags":514},"https://github.com/apache/commons-fileupload",[476],[515],"PACKAGE",[],{"date":518,"score":465,"percentile":519},"2026-06-04",0.79901,[521,525,528,531,534,536,539,542,545,549,553,556,559,562,565,569,573,576,579,582,586,590,594,597,600,603,606,609,613,616,619,622,625,629,632,635,638,641,644,647,650,653,656,659,662,666,669,673,676,679,682,685,688,691,694,697,700,703,706,709,713,716,719,722,725,728,731,734,738,741,744,747,750,753,756,759,762,765,768,771,774,777,780,783,786,789,792,796,799,802],{"date":522,"score":523,"percentile":524},"2025-11-04",0.00127,0.32792,{"date":526,"score":523,"percentile":527},"2025-11-05",0.32775,{"date":529,"score":523,"percentile":530},"2025-11-06",0.32777,{"date":532,"score":523,"percentile":533},"2025-11-07",0.32794,{"date":535,"score":523,"percentile":524},"2025-11-08",{"date":537,"score":523,"percentile":538},"2025-11-09",0.32768,{"date":540,"score":523,"percentile":541},"2025-11-10",0.32715,{"date":543,"score":523,"percentile":544},"2025-11-11",0.32739,{"date":546,"score":547,"percentile":548},"2025-11-12",0.00098,0.27784,{"date":550,"score":551,"percentile":552},"2025-11-13",0.00094,0.27096,{"date":554,"score":551,"percentile":555},"2025-11-14",0.27082,{"date":557,"score":551,"percentile":558},"2025-11-15",0.27071,{"date":560,"score":551,"percentile":561},"2025-11-16",0.27026,{"date":563,"score":551,"percentile":564},"2025-11-17",0.26994,{"date":566,"score":567,"percentile":568},"2025-11-18",0.00536,0.64877,{"date":570,"score":571,"percentile":572},"2025-11-19",0.00072,0.17944,{"date":574,"score":571,"percentile":575},"2025-11-20",0.17918,{"date":577,"score":571,"percentile":578},"2025-11-21",0.2204,{"date":580,"score":551,"percentile":581},"2025-11-22",0.26996,{"date":583,"score":584,"percentile":585},"2025-11-23",0.00081,0.24245,{"date":587,"score":588,"percentile":589},"2025-11-24",0.00144,0.3527,{"date":591,"score":592,"percentile":593},"2025-11-25",0.00109,0.29873,{"date":595,"score":592,"percentile":596},"2025-11-26",0.29872,{"date":598,"score":588,"percentile":599},"2025-11-27",0.35276,{"date":601,"score":588,"percentile":602},"2025-11-28",0.35256,{"date":604,"score":588,"percentile":605},"2025-11-29",0.35235,{"date":607,"score":588,"percentile":608},"2025-11-30",0.35215,{"date":610,"score":611,"percentile":612},"2025-12-01",0.00146,0.35551,{"date":614,"score":611,"percentile":615},"2025-12-02",0.35559,{"date":617,"score":611,"percentile":618},"2025-12-03",0.35557,{"date":620,"score":588,"percentile":621},"2025-12-04",0.35214,{"date":623,"score":588,"percentile":624},"2025-12-05",0.35245,{"date":626,"score":627,"percentile":628},"2025-12-06",0.00168,0.38345,{"date":630,"score":627,"percentile":631},"2025-12-07",0.38323,{"date":633,"score":627,"percentile":634},"2025-12-08",0.38336,{"date":636,"score":627,"percentile":637},"2025-12-09",0.38377,{"date":639,"score":627,"percentile":640},"2025-12-10",0.38437,{"date":642,"score":627,"percentile":643},"2025-12-11",0.38465,{"date":645,"score":627,"percentile":646},"2025-12-12",0.38499,{"date":648,"score":627,"percentile":649},"2025-12-13",0.38475,{"date":651,"score":627,"percentile":652},"2025-12-14",0.38438,{"date":654,"score":627,"percentile":655},"2025-12-15",0.38413,{"date":657,"score":627,"percentile":658},"2025-12-16",0.38447,{"date":660,"score":627,"percentile":661},"2025-12-17",0.38493,{"date":663,"score":664,"percentile":665},"2025-12-18",0.00148,0.36024,{"date":667,"score":664,"percentile":668},"2025-12-19",0.36041,{"date":670,"score":671,"percentile":672},"2025-12-20",0.00196,0.41839,{"date":674,"score":671,"percentile":675},"2025-12-21",0.41797,{"date":677,"score":671,"percentile":678},"2025-12-22",0.41771,{"date":680,"score":671,"percentile":681},"2025-12-23",0.41774,{"date":683,"score":671,"percentile":684},"2025-12-24",0.41791,{"date":686,"score":671,"percentile":687},"2025-12-25",0.4184,{"date":689,"score":671,"percentile":690},"2025-12-26",0.41821,{"date":692,"score":671,"percentile":693},"2025-12-27",0.41834,{"date":695,"score":671,"percentile":696},"2025-12-28",0.41751,{"date":698,"score":671,"percentile":699},"2025-12-29",0.41734,{"date":701,"score":588,"percentile":702},"2025-12-30",0.35249,{"date":704,"score":588,"percentile":705},"2025-12-31",0.35302,{"date":707,"score":611,"percentile":708},"2026-01-01",0.3567,{"date":710,"score":711,"percentile":712},"2026-01-02",0.0017,0.38834,{"date":714,"score":711,"percentile":715},"2026-01-03",0.38831,{"date":717,"score":627,"percentile":718},"2026-01-04",0.38433,{"date":720,"score":627,"percentile":721},"2026-01-05",0.38405,{"date":723,"score":627,"percentile":724},"2026-01-06",0.38411,{"date":726,"score":627,"percentile":727},"2026-01-07",0.38434,{"date":729,"score":627,"percentile":730},"2026-01-08",0.38461,{"date":732,"score":627,"percentile":733},"2026-01-09",0.38454,{"date":735,"score":736,"percentile":737},"2026-01-10",0.00225,0.45067,{"date":739,"score":736,"percentile":740},"2026-01-11",0.45048,{"date":742,"score":736,"percentile":743},"2026-01-12",0.44997,{"date":745,"score":736,"percentile":746},"2026-01-13",0.44973,{"date":748,"score":736,"percentile":749},"2026-01-14",0.45022,{"date":751,"score":736,"percentile":752},"2026-01-15",0.45018,{"date":754,"score":736,"percentile":755},"2026-01-16",0.45037,{"date":757,"score":736,"percentile":758},"2026-01-17",0.45011,{"date":760,"score":711,"percentile":761},"2026-01-18",0.38643,{"date":763,"score":711,"percentile":764},"2026-01-19",0.38613,{"date":766,"score":711,"percentile":767},"2026-01-20",0.38595,{"date":769,"score":711,"percentile":770},"2026-01-21",0.38583,{"date":772,"score":711,"percentile":773},"2026-01-22",0.38578,{"date":775,"score":711,"percentile":776},"2026-01-23",0.38638,{"date":778,"score":736,"percentile":779},"2026-01-24",0.45019,{"date":781,"score":736,"percentile":782},"2026-01-25",0.44963,{"date":784,"score":736,"percentile":785},"2026-01-26",0.44922,{"date":787,"score":736,"percentile":788},"2026-01-27",0.44926,{"date":790,"score":736,"percentile":791},"2026-01-28",0.44931,{"date":793,"score":794,"percentile":795},"2026-01-29",0.00193,0.41191,{"date":797,"score":794,"percentile":798},"2026-01-30",0.41198,{"date":800,"score":794,"percentile":801},"2026-01-31",0.41205,{"date":803,"score":804,"percentile":805},"2026-02-01",0.00167,0.38136,[807,812,814],{"source":469,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":808,"cvss_v4_0":9},{"baseScore":467,"baseSeverity":809,"vectorString":470,"impactScore":810,"exploitabilityScore":811},"HIGH",6,10,{"source":475,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":813,"cvss_v4_0":9},{"baseScore":467,"baseSeverity":809,"vectorString":470,"impactScore":810,"exploitabilityScore":811},{"source":476,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":815},{"baseScore":816,"baseSeverity":9,"vectorString":817,"impactScore":9,"exploitabilityScore":9},8.7,"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",[819,836,856,866],{"ecosystem":9,"name":820,"vendor":821,"product":822,"cpe_part":823,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":824},"Apache Commons FileUpload","apache software foundation","apache commons fileupload","a",[825,832],{"version":826,"is_range":827,"range_type":469,"version_start":828,"version_start_type":829,"version_end":830,"version_end_type":831,"fixed_in":9},">= 1.0, \u003C 1.6",true,"1.0","including","1.6","excluding",{"version":833,"is_range":827,"range_type":469,"version_start":834,"version_start_type":829,"version_end":835,"version_end_type":831,"fixed_in":9},">= 2.0.0-M1, \u003C 2.0.0-M4","2.0.0-M1","2.0.0-M4",{"ecosystem":9,"name":837,"vendor":838,"product":839,"cpe_part":823,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":840},"commons fileupload","apache","commons_fileupload",[841,844,846,848,850,852,854],{"version":842,"is_range":827,"range_type":843,"version_start":828,"version_start_type":829,"version_end":830,"version_end_type":831,"fixed_in":9},"gte1.0_lt1.6","cpe",{"version":845,"is_range":463,"range_type":843,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.0.0:m1",{"version":847,"is_range":463,"range_type":843,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.0.0:m1-rc1",{"version":849,"is_range":463,"range_type":843,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.0.0:m2",{"version":851,"is_range":463,"range_type":843,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.0.0:m2-rc1",{"version":853,"is_range":463,"range_type":843,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.0.0:m3",{"version":855,"is_range":463,"range_type":843,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.0.0:m3-rc1",{"ecosystem":857,"name":858,"vendor":859,"product":859,"cpe_part":9,"purl_type":860,"purl_namespace":859,"purl_name":859,"source":9,"versions":861},"Maven","commons-fileupload:commons-fileupload","commons-fileupload","maven",[862],{"version":863,"is_range":827,"range_type":864,"version_start":828,"version_start_type":829,"version_end":865,"version_end_type":831,"fixed_in":9},"gte1_0_lt1_6_0","ecosystem","1.6.0",{"ecosystem":857,"name":867,"vendor":868,"product":869,"cpe_part":9,"purl_type":860,"purl_namespace":868,"purl_name":869,"source":9,"versions":870},"org.apache.commons:commons-fileupload2-core","org.apache.commons","commons-fileupload2-core",[871],{"version":872,"is_range":827,"range_type":864,"version_start":834,"version_start_type":829,"version_end":835,"version_end_type":831,"fixed_in":9},"gte2_0_0_M1_lt2_0_0_M4"]