CVE-2025-48976 is a denial-of-service vulnerability in Apache Commons FileUpload caused by insufficient limits on resource allocation while processing multipart part headers. An attacker can submit multipart data with headers that drive excessive resource consumption, potentially making an affected service unavailable. Apache Commons FileUpload versions 1.0 through before 1.6 and 2.0.0-M1 through before 2.0.0-M4 are affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Python proof-of-concept exploit script (1.py) and a brief README. The script targets a web application's file upload endpoint (http://192.168.249.128:8080/MultipartUploadApp_JSP/upload.jsp) by sending repeated multipart/form-data POST requests. Each request is crafted to contain 100 parts, and each part includes 50 large custom headers, resulting in a very large and complex request body. The script runs in an infinite loop, sending these payloads and printing the response status and size. This behavior is typical for testing vulnerabilities such as resource exhaustion, denial of service, or improper handling of multipart requests. The README references CVE-2025-48976 and CVE-2025-48988, suggesting the script is a POC for these vulnerabilities. No additional payload or post-exploitation functionality is present; the script's main purpose is to trigger and observe the application's response to the crafted requests.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-48988 and CVE-2025-48976, targeting Apache Tomcat 10.1.41 running a Jakarta Servlet file upload endpoint. The structure includes a Dockerfile to build and run a vulnerable Tomcat instance with a custom UploadServlet at /upload, a Java servlet source file, a web.xml configuration mapping the servlet, and a Python exploit script. The exploit script (exploit-cve-2025-48988.py) sends a large number of multipart POST requests with many parts and headers to the /upload endpoint, causing high CPU usage and potential denial of service. The README provides setup, usage, and remediation instructions, including upgrading Tomcat to 10.1.42 to mitigate the vulnerability. The main attack vector is network-based, targeting the HTTP file upload endpoint. The repository is well-structured for demonstrating and testing the DoS vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
52 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A denial-of-service vulnerability in Apache Commons FileUpload caused by multipart part-header processing.
Unknown (Hitachi advisory indicates a vulnerability in Hitachi Command Suite components affecting multiple Hitachi management products; specific flaw type/impact not provided in the content).
Unknown (listed as a trending CVE; associated in the list with Atlassian, but no technical details provided).
A denial-of-service vulnerability in Apache Commons FileUpload 2 (org.apache.commons:commons-fileupload2-core) dependency affecting Atlassian Crowd Data Center/Server.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.