The javax.servlet package lacks support for RFC-1867, HTML file upload. This package provides a simple to use API for working with such data. The scope of this package is to create a package of Java utility classes to read multipart/form-data within a javax.servlet.http.HttpServletRequest.
Security Fix(es):
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.
This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4.
Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.(CVE-2025-48976)
{ "severity": "High" }
{ "src": [ "apache-commons-fileupload-1.4-3.oe2403.src.rpm", "apache-commons-fileupload-1.4-3.oe2403sp1.src.rpm" ], "noarch": [ "apache-commons-fileupload-1.4-3.oe2403.noarch.rpm", "apache-commons-fileupload-help-1.4-3.oe2403.noarch.rpm", "apache-commons-fileupload-1.4-3.oe2403sp1.noarch.rpm", "apache-commons-fileupload-help-1.4-3.oe2403sp1.noarch.rpm" ] }