Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-24998

51
FAUCET Score

CVE-2023-24998 is a denial-of-service (DoS) vulnerability in Apache Commons FileUpload versions prior to 1.5, affecting products like Apache Commons FileUpload and Debian Linux. This flaw allows an unauthenticated attacker to trigger a DoS by sending a malicious upload or series of uploads, as the software does not limit the number of request parts processed. Rated with a CVSS score of 7.5 (High), it presents a low-complexity attack vector with a high impact on availability. While there is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, the vulnerability has garnered significant community discussion and media coverage, indicating awareness of its potential impact.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0, < 1.5CPE matchmatch criteria
cpe:2.3:a:apache:commons_fileupload:*:*:*:*:*:*:*:*
1.0CPE matchmatch criteria
cpe:2.3:a:apache:commons_fileupload:1.0:beta:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
11.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
46.84%
Probability of exploitation in next 30 days
EPSS Percentile
98.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.4684 is in the 98th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (39)

mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-coyoteFixed in: 10.1.5
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-coyoteFixed in: 11.0.0-M5
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-coyoteFixed in: 8.5.88
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-coyoteFixed in: 9.0.71
mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 10.1.5
mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 11.0.0-M5
mavenpatch availablevia ghsa
Product: commons-fileupload:commons-fileuploadFixed in: 1.5
mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 8.5.88
mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 9.0.71
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-catalinaFixed in: 10.1.5
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-catalinaFixed in: 11.0.0-M5
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-catalinaFixed in: 8.5.88
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-catalinaFixed in: 9.0.71
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.7 on RHEL 9Fixed in: jws5-tomcat-0:9.0.62-15.redhat_00013.1.el9jws
View patch
redhatpatch availablevia redhat_api
Product: JWS 5.7.4 releaseFixed in: tomcat
View patch
redhatpatch availablevia redhat_api
Product: OCP-Tools-4.13-RHEL-8Fixed in: jenkins-0:2.387.3.1684911776-3.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: tomcat-1:9.0.62-27.el8_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: tomcat-1:9.0.62-37.el9_3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.7 on RHEL 7Fixed in: jws5-tomcat-0:9.0.62-15.redhat_00013.1.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.7 on RHEL 8Fixed in: jws5-tomcat-0:9.0.62-15.redhat_00013.1.el8jws
View patch
redhatpatch availablevia redhat_api
Product: RHINT Camel-Springboot 3.20.1Fixed in: tomcat
View patch
redhatpatch availablevia redhat_api
Product: RHPAM 7.13.4 async
View patch
redhatno patchvia redhat_api
Product: Red Hat support for Spring BootFixed in: tomcat
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: tomcat
redhatno patchvia redhat_api
Product: Red Hat Integration Camel K 1Fixed in: camel
redhatno patchvia redhat_api
Product: Red Hat Integration Camel K 1Fixed in: tomcat
redhatno patchvia redhat_api
Product: Red Hat OpenShift Application RuntimesFixed in: tomcat
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: jenkins
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pki-servlet-engine
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: pki-servlet-engine
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Application RuntimesFixed in: httl
redhatend of lifevia redhat_api
Product: Migration Toolkit for Applications 6Fixed in: org.keycloak-keycloak-parent
redhatend of lifevia redhat_api
Product: Red Hat Integration Camel Quarkus 1Fixed in: camel-quarkus
redhatend of lifevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: log4j
redhatend of lifevia redhat_api
Product: Red Hat build of Debezium 1Fixed in: commons-fileupload
redhatend of lifevia redhat_api
Product: Red Hat Data Grid 8Fixed in: commons-fileupload
redhatend of lifevia redhat_api
Product: Red Hat Data Grid 8Fixed in: tomcat
redhatend of lifevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: tomcat
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pki-deps:10.6/pki-servlet-engine

Vendor Advisories (2)

mavenGHSA-hfrx-6qgj-fp6chigh

Apache Commons FileUpload denial of service vulnerability

Feb 20, 2023
redhatCVE-2023-24998Moderate

FileUpload: FileUpload DoS with excessive parts

Feb 20, 2023

References

lists.debian.org / debian-lts-announce/2025/07/msg00008.html
security.netapp.com / advisory/ntap-20230302-0013
security.netapp.com / advisory/ntap-20241108-0002
lists.apache.org / thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy
Mailing ListVendor Advisory
lists.debian.org / debian-lts-announce/2023/10/msg00020.html
Third Party Advisory
security.gentoo.org / glsa/202305-37
Third Party Advisory
debian.org / security/2023/dsa-5522
Third Party Advisory
openwall.com / lists/oss-security/2023/05/22/1
Mailing List