{"id":"CVE-2025-48976","details":"Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.\n\nThis issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4.\n\nUsers are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.","aliases":["GHSA-vv7r-c36w-3prj"],"modified":"2026-04-16T00:00:56.423375949Z","published":"2025-06-16T15:15:24.460Z","related":["ALSA-2025:14177","ALSA-2025:14178","ALSA-2025:14181","CGA-jwxx-8jj7-h645","SUSE-SU-2025:02159-1","SUSE-SU-2025:02184-1","openSUSE-SU-2025:15208-1"],"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/07/msg00008.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/fbs3wrr3p67vkjcxogqqqqz45pqtso12"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2025/06/16/4"},{"type":"ARTICLE","url":"https://lists.apache.org/thread/fbs3wrr3p67vkjcxogqqqqz45pqtso12"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2025/06/16/4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/commons-fileupload","events":[{"introduced":"cdfbeaa120cba6a8f1527b91600317ee374450c2"},{"fixed":"f3e030f09ac8b01b684466c793dec86eafe1e4c9"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-48976.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}