GHSA-hfrx-6qgj-fp6c · Severity: high · Ecosystem: maven — Apache Commons FileUpload denial of service vulnerability
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.
Conclusion & alert: CVE-2023-24998 is rated Moderate Risk (60.1/100): CVSS High severity, with high exploitation likelihood (EPSS 33.90%, 97th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-27 | 37.74% | 33.90% | -3.84% |
| 2 | 2026-05-26 | 37.16% | 37.74% | +0.58% |
| 3 | 2026-05-20 | — | 37.16% | — |
Full EPSS history (74 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-hfrx-6qgj-fp6c · Severity: high · Ecosystem: maven — Apache Commons FileUpload denial of service vulnerability
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2023-24998 not yet assigned priority: Debian including 3 source packages (libcommons-fileupload-java, tomcat10, tomcat9), 14 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 14. | https://security-tracker.debian.org/tracker/CVE-2023-24998 |
gentoo
|
low | CVE-2023-24998: 1 GLSA(s) (202305-37), 1 atom(s) (www-servers/tomcat); latest impact low. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2023-24998 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2023-24998 |
suse
|
high | — | https://www.suse.com/security/cve/CVE-2023-24998/ |
ubuntu
|
medium | CVE-2023-24998 medium priority: Ubuntu including 1 source packages (libcommons-fileupload-java), 13 status rows across 13 suites (bionic, focal, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): needs-triage 7, ignored 6. | https://ubuntu.com/security/CVE-2023-24998 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | commons_fileupload | >= 1.0, < 1.5 | cpe:2.3:a:apache:commons_fileupload:*:*:*:*:*:*:*:* |
| apache | commons_fileupload | 1.0 | cpe:2.3:a:apache:commons_fileupload:1.0:beta:*:*:*:*:*:* |
| debian | debian_linux | 9.0 | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
| debian | debian_linux | 11.0 | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2023/05/22/1 | Mailing List |
| https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy | Mailing List Vendor Advisory |
| https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html | Third Party Advisory |
| https://security.gentoo.org/glsa/202305-37 | Third Party Advisory |
| https://www.debian.org/security/2023/dsa-5522 | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2025/07/msg00008.html | |
| https://security.netapp.com/advisory/ntap-20230302-0013/ | |
| https://security.netapp.com/advisory/ntap-20241108-0002/ |