CVE-2023-24998: Apache Commons Fileupload

High severity, CVSS 7.5. EPSS: 48.8% chance of exploitation in the next 30 days.

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

Affected products

  • Apache Commons Fileupload: from 1.0, before 1.5 (fixed in 1.5); version 1.0 only
  • Debian Debian Linux: version 9.0 only; version 11.0 only

Published 2023-02-20. Last modified 2026-10-07.