CVE-2014-0050
Apache Commons FileUpload <1.3.1 - DoS
Title source: llmDescription
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
Exploits (5)
exploitdb
WORKING POC
VERIFIED
by Trustwave's SpiderLabs · rubydosmultiple
https://www.exploit-db.com/exploits/31615
nomisec
WRITEUP
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2014-0050-commons-fileupload-vulnerable
nomisec
WRITEUP
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2014-0050-commons-fileupload-vulnerable
metasploit
WORKING POC
by Unknown, ribeirux · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/http/apache_commons_fileupload_dos.rb
References (69)
... and 49 more
Scores
EPSS
0.9271
EPSS Percentile
99.8%
Details
CWE
CWE-264
Status
published
Products (47)
apache/commons_fileupload
1.0
apache/commons_fileupload
1.1
apache/commons_fileupload
1.1.1
apache/commons_fileupload
1.2
apache/commons_fileupload
1.2.1
apache/commons_fileupload
1.2.2
apache/commons_fileupload
< 1.3
apache/tomcat
7.0.0 (2 CPE variants)
apache/tomcat
7.0.1
apache/tomcat
7.0.2 (2 CPE variants)
... and 37 more
Published
Apr 01, 2014
Tracked Since
Feb 18, 2026