← Search the atlas
SUSE-SU-2025:02159-1
Not scored
Security update for apache-commons-fileupload
This update for apache-commons-fileupload fixes the following issues:
Upgrade to upstream version 1.6.0
- CVE-2025-48976: Fixed allocation of resources for multipart headers with insufficient limits can lead to a DoS (bsc#1244657).
Full changelog:
https://commons.apache.org/proper/commons-fileupload/changes.html#a1.6.0
Exploit probability
Not scored
Published
June 27, 2025
Required by
Not available
Last source change
February 4, 2026
02 / AFFECTED SOFTWARE
Affected packages
openSUSE:Leap 15.6
apache-commons-fileupload
SUSE:Enterprise Storage 7.1
apache-commons-fileupload
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS
apache-commons-fileupload
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
apache-commons-fileupload
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
apache-commons-fileupload
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
apache-commons-fileupload
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
apache-commons-fileupload
SUSE:Linux Enterprise Module for Web and Scripting 15 SP6
apache-commons-fileupload
SUSE:Linux Enterprise Module for Web and Scripting 15 SP7
apache-commons-fileupload
SUSE:Linux Enterprise Server 15 SP3-LTSS
apache-commons-fileupload
SUSE:Linux Enterprise Server 15 SP4-LTSS
apache-commons-fileupload
SUSE:Linux Enterprise Server 15 SP5-LTSS
apache-commons-fileupload
SUSE:Linux Enterprise Server for SAP Applications 15 SP3
apache-commons-fileupload
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
apache-commons-fileupload
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
apache-commons-fileupload
SUSE:Manager Server 4.3
apache-commons-fileupload
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
SUSE-SU-2025:02159-1
This update for apache-commons-fileupload fixes the following issues:
Upgrade to upstream version 1.6.0
- CVE-2025-48976: Fixed allocation of resources for multipart headers with insufficient limits can lead to a DoS (bsc#1244657).
Full changelog:
https://commons.apache.org/proper/commons-fileupload/changes.html#a1.6.0
View original source ↗
05 / REFERENCES
Further evidence