FlawAtlas
Search the atlas
CVE-2014-0050 High

CVE-2014-0050

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.

Exploit probability 83.2%
Published April 1, 2014
Required by Not available
Last source change April 16, 2026

02 / AFFECTED SOFTWARE

Affected packages

Maven commons-fileupload:commons-fileupload

9 explicit affected versions

Maven org.apache.tomcat:tomcat

13 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2014-0050

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.

View original source
Open Source Vulnerabilities GHSA-xx68-jfcg-xmmf

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.

View original source

05 / REFERENCES

Further evidence