CVE-2023-24998High· 7.5▾ MidnightPoC availableApache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the fil…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 9.8 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
49%
1 GitHub repo (last check)
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.
Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.
commons_fileupload >= 1.0, < 1.5commons_fileupload = 1.0debian_linux = 9.0debian_linux = 11.0Upgrade past the affected range:
commons_fileupload 1.5Connected by shared product, vendor, weakness, or advisory.
CVE-2022-36124High· 7.5It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system
CVE-2026-102496High· 7.5Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse until the stack overflows
CVE-2026-102495High· 7.5Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows
CVE-2026-92550High· 7.5A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to ve…
CVE-2026-92564High· 7.5A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1…
CVE-2026-92560High· 7.5A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to ve…