Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Debian: Critical DoS Vulnerability in libcommons-fileupload-java DLA-4245-1

debian lts
Calendar Grey July 22, 2025
Dist Debian Esm H88
Two significant security flaws identified in libcommons-fileupload-java necessitate urgent action and patching for Debian users.
Two security vulnerabilities have been found in libcommons-fileupload-java, a Java library that adds robust, high-performance, file upload capability to your servlets and web appli...

Summary

CVE-2023-24998:

Apache Commons FileUpload does not limit the number of request
parts to be processed resulting in the possibility of an attacker
triggering a DoS with a malicious upload or series of uploads. Note that,
like all of the file upload limits, the new configuration option
(FileUploadBase#setFileCountMax) is not enabled by default and must be
explicitly configured.

CVE-2025-48976:

Allocation of resources for multipart headers with insufficient limits
enabled a DoS vulnerability in Apache Commons FileUpload.

For Debian 11 bullseye, these problems have been fixed in version
1.4-1+deb11u1.

We recommend that you upgrade your libcommons-fileupload-java packages.

For the detailed security status of libcommons-fileupload-java please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libcommons-fileupload-java

Further information about Debian LTS security advisories, how to apply

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: libcommons-fileupload-java
Version: 1.4-1+deb11u1
CVE ID: CVE-2023-24998 CVE-2025-48976
Debian Bug: 1031733 1108120

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here