CVE-2016-3092: Apache Commons Fileupload
High severity, CVSS 7.5. EPSS: 37.2% chance of exploitation in the next 30 days.
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
Affected products
- Apache Commons Fileupload: up to and including 1.3.1
- Apache Tomcat: version 9.0.0 only; version 8.0.0 only; version 8.0.1 only; version 8.0.3 only; version 8.0.5 only; version 8.0.8 only; …
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
- Debian Debian Linux: version 8.0 only
- HP Icewall Identity Manager: version 5.0 only
- HP Icewall SSO Agent Option: version 10.0 only
Published 2016-07-04. Last modified 2026-10-07.