CVE-2016-3092
Executive Summary
Apache Commons Fileupload (v1.3.2 and earlier) and Apache Tomcat (7.x <7.0.70, 8.x <8.0.36, 8.5.x <8.5.3, 9.x <9.0.0.M7) are vulnerable to a denial‑of‑service attack. Remote attackers can send a multipart request with an excessively long boundary string, causing the MultipartStream parser to consume excessive CPU and potentially crash the server. The flaw is mitigated by upgrading to the affected libraries’ patched versions.
Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2016-07-04T22:59:04.303 - Last Modified: 2026-10-07T18:17:07.770
Original Description: The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
"Fear not for the future, weep not for the past."
— Percy Shelley