---
id: CVE-2023-24998
title: >-
  Apache Commons FileUpload before 1.5 does not limit the number of request
  parts to be processed resulting in the possibility of an attacker triggering a
  DoS with a malicious upload or series of uploads.





  Note that, like all of the fil…
summary: >-
  Apache Commons FileUpload before 1.5 does not limit the number of request
  parts to be processed resulting in the possibility of an attacker triggering a
  DoS with a malicious upload or series of uploads.





  Note that, like all of the fil…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
vendor: apache
product: commons_fileupload
affected:
  - 'commons_fileupload >= 1.0, < 1.5'
  - commons_fileupload = 1.0
  - debian_linux = 9.0
  - debian_linux = 11.0
patched:
  - commons_fileupload 1.5
published: '2023-02-20'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T17:16:43.860'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-24998'
references:
  - url: 'http://www.openwall.com/lists/oss-security/2023/05/22/1'
    label: security@apache.org
  - url: 'https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy'
    label: security@apache.org
  - url: 'https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html'
    label: security@apache.org
  - url: 'https://security.gentoo.org/glsa/202305-37'
    label: security@apache.org
  - url: 'https://www.debian.org/security/2023/dsa-5522'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2023/05/22/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2025/07/msg00008.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202305-37'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20230302-0013/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20241108-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2023/dsa-5522'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
  - exploit-available
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2025-06-03T19:22:53.244328Z'
epss: 0.48788
epssPercentile: 0.98847
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/nice1st/CVE-2023-24998'
  checkedAt: '2026-10-07T17:41:11.301Z'
exploitAvailable: true
ingestedAt: '2026-10-07T16:38:22.239Z'
---

## Overview

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.




Note that, like all of the file upload limits, the
          new configuration option (FileUploadBase#setFileCountMax) is not
          enabled by default and must be explicitly configured.

## Affected

- `commons_fileupload >= 1.0, < 1.5`
- `commons_fileupload = 1.0`
- `debian_linux = 9.0`
- `debian_linux = 11.0`

## Remediation

Upgrade past the affected range:

- `commons_fileupload 1.5`
