apache-commons-fileupload: denial of service due to too-small buffer size used by MultipartStream
Published Mar 28, 2014
7.5
HIGHCVSS 2.0
EPSS 83.17%
Description
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
Affected products
No data.
Configuration 1
- 12.0
- 12.0in
- 13.0
- 13.1
- 13.2
- 13.3
- 13.4
- 14.0
Configuration 2
- ≤ 1.3
- 1.0
- 1.1
- 1.1.1
- 1.2
- 1.2.1
- 1.2.2
- 7.0.0
- 7.0.0
- 7.0.1
- 7.0.2
- 7.0.2
- 7.0.3
- 7.0.4
- 7.0.4
- 7.0.5
- 7.0.6
- 7.0.7
- 7.0.8
- 7.0.9
- 7.0.10
- 7.0.11
- 7.0.12
- 7.0.13
- 7.0.14
- 7.0.15
- 7.0.16
- 7.0.17
- 7.0.18
- 7.0.19
- 7.0.20
- 7.0.21
- 7.0.22
- 7.0.23
- 7.0.24
- 7.0.25
- 7.0.26
- 7.0.27
- 7.0.28
- 7.0.29
- 7.0.30
- 7.0.31
- 7.0.32
- 7.0.33
- 7.0.34
- 7.0.35
- 7.0.36
- 7.0.37
- 7.0.38
- 7.0.39
- 7.0.40
- 7.0.41
- 7.0.42
- 7.0.43
- 7.0.44
- 7.0.45
- 7.0.46
- 7.0.47
- 7.0.48
- 7.0.49
- 7.0.50
- 8.0.0
- 8.0.0
- 8.0.0
- 8.0.0
- 8.0.1
No data.
Fuse ESB Enterprise 7.1.0
n/a
Fixed · RHSA-2014:0452
Fuse MQ Enterprise 7.1.0
n/a
Fixed · RHSA-2014:0452
Fuse Management Console 7.1.0
n/a
Fixed · RHSA-2014:0452
Red Hat Enterprise Linux 6
tomcat6-0:6.0.24-64.el6_5
Fixed · RHSA-2014:0429
Red Hat JBoss A-MQ 6.1
n/a
Fixed · RHSA-2014:0401
Red Hat JBoss BPMS 6.0
jbossweb
Fixed · RHSA-2014:0373
Red Hat JBoss BRMS 6.0
jbossweb
Fixed · RHSA-2014:0373
Red Hat JBoss Enterprise Application Platform 6.2
jbossweb
Fixed · RHSA-2014:0252
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5
jbossweb-0:7.3.0-2.Final_redhat_2.1.ep6.el5
Fixed · RHSA-2014:0253
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 6
jbossweb-0:7.3.0-2.Final_redhat_2.1.ep6.el6
Fixed · RHSA-2014:0253
Red Hat JBoss Enterprise Web Server 2 for RHEL 5
tomcat6-0:6.0.37-19_patch_04.ep6.el5
Fixed · RHSA-2014:0525
Red Hat JBoss Enterprise Web Server 2 for RHEL 5
tomcat7-0:7.0.40-13_patch_02.ep6.el5
Fixed · RHSA-2014:0526
Red Hat JBoss Enterprise Web Server 2 for RHEL 6
tomcat6-0:6.0.37-27_patch_04.ep6.el6
Fixed · RHSA-2014:0525
Red Hat JBoss Enterprise Web Server 2 for RHEL 6
tomcat7-0:7.0.40-9_patch_02.ep6.el6
Fixed · RHSA-2014:0526
Red Hat JBoss Fuse 6.1
n/a
Fixed · RHSA-2014:0400
Red Hat JBoss Fuse Service Works 6.0
jbossweb
Fixed · RHSA-2014:0459
Red Hat JBoss Operations Network 3.2
n/a
Fixed · RHSA-2014:0473
Red Hat JBoss Portal 6.2
jbossweb
Fixed · RHSA-2015:1009
Red Hat JBoss Web Server 2.0
tomcat6
Fixed · RHSA-2014:0528
Red Hat JBoss Web Server 2.0
tomcat7
Fixed · RHSA-2014:0527
Red Hat BPM Suite 6
commons-fileupload
Affected
Red Hat Enterprise Linux 5
jakarta-commons-fileupload
Under investigation
Red Hat Enterprise Linux 7
tomcat
Not affected
Red Hat JBoss BRMS 5
commons-fileupload
Will not fix
Red Hat JBoss BRMS 6
commons-fileupload
Affected
Red Hat JBoss Data Grid 6
jbossweb
Not affected
Red Hat JBoss Data Virtualization 6
jbossweb
Not affected
Red Hat JBoss Enterprise Web Server 1
commons-fileupload
Will not fix
Red Hat JBoss Enterprise Web Server 1
tomcat
Will not fix
Red Hat JBoss Fuse Service Works 6
commons-fileupload
Affected
Red Hat JBoss Operations Network 3
commons-fileupload
Affected
Red Hat JBoss Operations Network 3
jbossweb
Affected
Red Hat JBoss Portal 4
commons-fileupload
Will not fix
Red Hat JBoss Portal 5
commons-fileupload
Will not fix
Red Hat JBoss Portal 6
commons-fileupload
Affected
Red Hat JBoss SOA Platform 4
commons-fileupload
Will not fix
Red Hat JBoss SOA Platform 5
commons-fileupload
Will not fix
Red Hat Satellite 5
commons-fileupload
Will not fix
Red Hat Satellite 6
commons-fileupload
Will not fix
Red Hat Software Collections
thermostat1-apache-commons-fileupload
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Fuse ESB Enterprise 7.1.0 | n/a | Fixed | RHSA-2014:0452 |
| Fuse MQ Enterprise 7.1.0 | n/a | Fixed | RHSA-2014:0452 |
| Fuse Management Console 7.1.0 | n/a | Fixed | RHSA-2014:0452 |
| Red Hat Enterprise Linux 6 | tomcat6-0:6.0.24-64.el6_5 | Fixed | RHSA-2014:0429 |
| Red Hat JBoss A-MQ 6.1 | n/a | Fixed | RHSA-2014:0401 |
| Red Hat JBoss BPMS 6.0 | jbossweb | Fixed | RHSA-2014:0373 |
| Red Hat JBoss BRMS 6.0 | jbossweb | Fixed | RHSA-2014:0373 |
| Red Hat JBoss Enterprise Application Platform 6.2 | jbossweb | Fixed | RHSA-2014:0252 |
| Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5 | jbossweb-0:7.3.0-2.Final_redhat_2.1.ep6.el5 | Fixed | RHSA-2014:0253 |
| Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 6 | jbossweb-0:7.3.0-2.Final_redhat_2.1.ep6.el6 | Fixed | RHSA-2014:0253 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 5 | tomcat6-0:6.0.37-19_patch_04.ep6.el5 | Fixed | RHSA-2014:0525 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 5 | tomcat7-0:7.0.40-13_patch_02.ep6.el5 | Fixed | RHSA-2014:0526 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | tomcat6-0:6.0.37-27_patch_04.ep6.el6 | Fixed | RHSA-2014:0525 |
| Red Hat JBoss Enterprise Web Server 2 for RHEL 6 | tomcat7-0:7.0.40-9_patch_02.ep6.el6 | Fixed | RHSA-2014:0526 |
| Red Hat JBoss Fuse 6.1 | n/a | Fixed | RHSA-2014:0400 |
| Red Hat JBoss Fuse Service Works 6.0 | jbossweb | Fixed | RHSA-2014:0459 |
| Red Hat JBoss Operations Network 3.2 | n/a | Fixed | RHSA-2014:0473 |
| Red Hat JBoss Portal 6.2 | jbossweb | Fixed | RHSA-2015:1009 |
| Red Hat JBoss Web Server 2.0 | tomcat6 | Fixed | RHSA-2014:0528 |
| Red Hat JBoss Web Server 2.0 | tomcat7 | Fixed | RHSA-2014:0527 |
| Red Hat BPM Suite 6 | commons-fileupload | Affected | n/a |
| Red Hat Enterprise Linux 5 | jakarta-commons-fileupload | Under investigation | n/a |
| Red Hat Enterprise Linux 7 | tomcat | Not affected | n/a |
| Red Hat JBoss BRMS 5 | commons-fileupload | Will not fix | n/a |
| Red Hat JBoss BRMS 6 | commons-fileupload | Affected | n/a |
| Red Hat JBoss Data Grid 6 | jbossweb | Not affected | n/a |
| Red Hat JBoss Data Virtualization 6 | jbossweb | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 1 | commons-fileupload | Will not fix | n/a |
| Red Hat JBoss Enterprise Web Server 1 | tomcat | Will not fix | n/a |
| Red Hat JBoss Fuse Service Works 6 | commons-fileupload | Affected | n/a |
| Red Hat JBoss Operations Network 3 | commons-fileupload | Affected | n/a |
| Red Hat JBoss Operations Network 3 | jbossweb | Affected | n/a |
| Red Hat JBoss Portal 4 | commons-fileupload | Will not fix | n/a |
| Red Hat JBoss Portal 5 | commons-fileupload | Will not fix | n/a |
| Red Hat JBoss Portal 6 | commons-fileupload | Affected | n/a |
| Red Hat JBoss SOA Platform 4 | commons-fileupload | Will not fix | n/a |
| Red Hat JBoss SOA Platform 5 | commons-fileupload | Will not fix | n/a |
| Red Hat Satellite 5 | commons-fileupload | Will not fix | n/a |
| Red Hat Satellite 6 | commons-fileupload | Will not fix | n/a |
| Red Hat Software Collections | thermostat1-apache-commons-fileupload | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 83.17% (0.83175) | 99.67th | v5 (v2026.06.15) |
| Jun 15, 2026 | 82.51% (0.82511) | 99.62th | v5 (v2026.06.15) |
| Mar 17, 2025 | 92.59% (0.92594) | 99.74th | v4 (v2025.03.14) |
| Feb 15, 2025 | 42.62% (0.42618) | 97.46th | v3 (v2023.03.01) |
| Dec 17, 2024 | 41.60% (0.41599) | 97.35th | v3 (v2023.03.01) |
| Dec 13, 2024 | 17.11% (0.17105) | 96.28th | v3 (v2023.03.01) |
| Oct 13, 2024 | 21.05% (0.21046) | 96.52th | v3 (v2023.03.01) |
| Jul 1, 2024 | 19.12% (0.19118) | 96.30th | v3 (v2023.03.01) |
| May 14, 2024 | 16.40% (0.16404) | 95.98th | v3 (v2023.03.01) |
| Dec 23, 2023 | 16.60% (0.16599) | 95.54th | v3 (v2023.03.01) |
| Sep 22, 2023 | 15.79% (0.15787) | 95.27th | v3 (v2023.03.01) |
| Mar 7, 2023 | 15.70% (0.15701) | 94.98th | v3 (v2023.03.01) |
| Mar 6, 2023 | 90.52% (0.90517) | 99.86th | v2 (v2022.01.01) |
| Sep 9, 2022 | 90.52% (0.90517) | 99.86th | v2 (v2022.01.01) |
| Feb 4, 2022 | 91.19% (0.91194) | 99.85th | v2 (v2022.01.01) |
References (81)
- http://advisories.mageia.org/MGASA-2014-0110.html x_refsource_CONFIRM
- http://blog.spiderlabs.com/2014/02/cve-2014-0050-exploit-with-boundaries-loops-without-boundaries.html x_refsource_MISCExploit
- http://jvn.jp/en/jp/JVN14876762/index.html third-party-advisoryx_refsource_JVN
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000017 third-party-advisoryx_refsource_JVNDB
- http://mail-archives.apache.org/mod_mbox/commons-dev/201402.mbox/%3C52F373FC.9030907%40apache.org%3E mailing-listx_refsource_MLIST
- http://mail-archives.apache.org/mod_mbox/commons-dev/201402.mbox/%3C52F373FC.9030907@apache.org%3E
- http://marc.info/?l=bugtraq&m=143136844732487&w=2 vendor-advisoryx_refsource_HP
- http://packetstormsecurity.com/files/127215/VMware-Security-Advisory-2014-0007.html x_refsource_MISC
- http://rhn.redhat.com/errata/RHSA-2014-0252.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2014-0253.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2014-0400.html vendor-advisoryx_refsource_REDHAT
- http://seclists.org/fulldisclosure/2014/Dec/23 mailing-listx_refsource_FULLDISC
- http://secunia.com/advisories/57915 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/58075 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/58976 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59039 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59041 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59183 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59184 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59185 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59187 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59232 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59399 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59492 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59500 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59725 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60475 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60753 third-party-advisoryx_refsource_SECUNIA
- http://svn.apache.org/r1565143 x_refsource_CONFIRMPatch
- http://tomcat.apache.org/security-7.html x_refsource_CONFIRMPatchVendor Advisory
- http://tomcat.apache.org/security-8.html x_refsource_CONFIRMPatchVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21669554 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21675432 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21676091 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21676092 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21676401 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21676403 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21676405 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21676410 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21676656 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21676853 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21677691 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21677724 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21681214 x_refsource_CONFIRM
- http://www.debian.org/security/2014/dsa-2856 vendor-advisoryx_refsource_DEBIAN
- http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-015/index.html x_refsource_CONFIRM
- http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-016/index.html x_refsource_CONFIRM
- http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-017/index.html x_refsource_CONFIRM
- http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-350733.htm x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:084 vendor-advisoryx_refsource_MANDRIVA
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html x_refsource_CONFIRM
- http://www.securityfocus.com/archive/1/532549/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/534161/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/65400 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-2130-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vmware.com/security/advisories/VMSA-2014-0007.html x_refsource_CONFIRM
- http://www.vmware.com/security/advisories/VMSA-2014-0008.html x_refsource_CONFIRM
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2014-0050 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1062337 x_refsource_CONFIRMIssue Tracking
- https://github.com/advisories/GHSA-xx68-jfcg-xmmf Advisory
- https://github.com/apache/commons-fileupload/commit/c61ff05b3241cb14d989b67209e57aa71540417a
- https://github.com/apache/tomcat/commit/29384723d8d9645b87e05be9fa369a4deeb78b9c
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324755 x_refsource_CONFIRM
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917 x_refsource_CONFIRM
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2014-0050
- https://security.gentoo.org/glsa/202107-39 vendor-advisoryx_refsource_GENTOO
- https://svn.apache.org/viewvc?view=revision&revision=1565143
- https://svn.apache.org/viewvc?view=revision&revision=1565163
- https://svn.apache.org/viewvc?view=revision&revision=1565169
- https://tomcat.apache.org/security-7.html
- https://tomcat.apache.org/security-8.html
- https://www.cve.org/CVERecord?id=CVE-2014-0050
Change history (0)
No recorded changes yet.