CVE-2014-0050: Apache Commons Fileupload

High severity, CVSS 7.5. EPSS: 83.3% chance of exploitation in the next 30 days.

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.

Affected products

  • Apache Commons Fileupload: up to and including 1.3; version 1.0 only; version 1.1 only; version 1.1.1 only; version 1.2 only; version 1.2.1 only; …
  • Apache Tomcat: version 7.0.0 only; version 7.0.1 only; version 7.0.2 only; version 7.0.3 only; version 7.0.4 only; version 7.0.5 only; …
  • Oracle Retail Applications: version 12.0 only; version 12.0in only; version 13.0 only; version 13.1 only; version 13.2 only; version 13.3 only; …

Published 2014-04-01. Last modified 2026-10-07.