FlawAtlas
Search the atlas
SUSE-SU-2025:02159-1 Not scored

Security update for apache-commons-fileupload

This update for apache-commons-fileupload fixes the following issues: Upgrade to upstream version 1.6.0 - CVE-2025-48976: Fixed allocation of resources for multipart headers with insufficient limits can lead to a DoS (bsc#1244657). Full changelog: https://commons.apache.org/proper/commons-fileupload/changes.html#a1.6.0

Exploit probability Not scored
Published June 27, 2025
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

openSUSE:Leap 15.6 apache-commons-fileupload
SUSE:Enterprise Storage 7.1 apache-commons-fileupload
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS apache-commons-fileupload
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS apache-commons-fileupload
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS apache-commons-fileupload
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS apache-commons-fileupload
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS apache-commons-fileupload
SUSE:Linux Enterprise Module for Web and Scripting 15 SP6 apache-commons-fileupload
SUSE:Linux Enterprise Module for Web and Scripting 15 SP7 apache-commons-fileupload
SUSE:Linux Enterprise Server 15 SP3-LTSS apache-commons-fileupload
SUSE:Linux Enterprise Server 15 SP4-LTSS apache-commons-fileupload
SUSE:Linux Enterprise Server 15 SP5-LTSS apache-commons-fileupload
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 apache-commons-fileupload
SUSE:Linux Enterprise Server for SAP Applications 15 SP4 apache-commons-fileupload
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 apache-commons-fileupload
SUSE:Manager Server 4.3 apache-commons-fileupload

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:02159-1

This update for apache-commons-fileupload fixes the following issues: Upgrade to upstream version 1.6.0 - CVE-2025-48976: Fixed allocation of resources for multipart headers with insufficient limits can lead to a DoS (bsc#1244657). Full changelog: https://commons.apache.org/proper/commons-fileupload/changes.html#a1.6.0

View original source

05 / REFERENCES

Further evidence