CVE-2014-0050High· 7.5▾ MidnightPoC availableMultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 16.6 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
83%
Exploit-DB · 1 GitHub repo · Metasploit ×1 (last check)
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
retail_applications = 12.0retail_applications = 12.0inretail_applications = 13.0retail_applications = 13.1retail_applications = 13.2retail_applications = 13.3retail_applications = 13.4retail_applications = 14.0commons_fileupload <= 1.3commons_fileupload = 1.0commons_fileupload = 1.1commons_fileupload = 1.1.1commons_fileupload = 1.2commons_fileupload = 1.2.1commons_fileupload = 1.2.2tomcat = 7.0.0tomcat = 7.0.1tomcat = 7.0.2tomcat = 7.0.3tomcat = 7.0.4tomcat = 7.0.5tomcat = 7.0.6tomcat = 7.0.7tomcat = 7.0.8tomcat = 7.0.9tomcat = 7.0.10tomcat = 7.0.11tomcat = 7.0.12tomcat = 7.0.13tomcat = 7.0.14tomcat = 7.0.15tomcat = 7.0.16tomcat = 7.0.17tomcat = 7.0.18tomcat = 7.0.19tomcat = 7.0.20tomcat = 7.0.21tomcat = 7.0.22tomcat = 7.0.23tomcat = 7.0.24tomcat = 7.0.25tomcat = 7.0.26tomcat = 7.0.27tomcat = 7.0.28tomcat = 7.0.29tomcat = 7.0.30tomcat = 7.0.31tomcat = 7.0.32tomcat = 7.0.33tomcat = 7.0.34tomcat = 7.0.35tomcat = 7.0.36tomcat = 7.0.37tomcat = 7.0.38tomcat = 7.0.39tomcat = 7.0.40tomcat = 7.0.41tomcat = 7.0.42tomcat = 7.0.43tomcat = 7.0.44tomcat = 7.0.45tomcat = 7.0.46tomcat = 7.0.47tomcat = 7.0.48tomcat = 7.0.49tomcat = 7.0.50tomcat = 8.0.0tomcat = 8.0.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34282High· 7.5Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking)
CVE-2026-106121Medium· 4.9The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes
CVE-2026-106116Medium· 5.3ImageSharp is a 2D graphics library
CVE-2026-87289High· 7.5Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content)
CVE-2026-87285Medium· 6.0Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)
CVE-2026-87284Low· 3.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)