StackRadar

CVE-2025-48976

High

Advisory

Published 16 Jun 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.626
99th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
86
of 17,781 indexed, latest versions
Container images
110
deployed by those charts
Fix available
2 of 2
affected packages

Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers

Carried by container images the latest versions of 86 of 17,781 indexed charts deploy, on 110 images.

Affected packageAffected versionsFixed inImages
commons-fileuploadmaven1.2.1, 1.3, 1.3.1, 1.3.1-jenkins-1+4 more1.6.0103
commons-fileupload2-coremaven2.0.0-M1, 2.0.0-M22.0.0-M48
OSV records
GHSA-vv7r-c36w-3prj

Charts affected

86 by stars
ChartLatestAffected imagesRadar Score
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
jingking/geonetwork-hnap:4.2.843e74ab234e1
commons-fileupload@1.3.3
1.6.0

Open the chart page →

34,754
metabasehelm-charts-nr0.14.41 of 1See more

metabase helm-charts-nr 0.14.4

1 of the 1 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
metabase/metabase:v0.45.21fb334ce4820
commons-fileupload@1.4
1.6.0

Open the chart page →

2,572
wiremockhelm-charts-nr1.4.61 of 2See more

wiremock helm-charts-nr 1.4.6

1 of the 2 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.26.03be08a386092
commons-fileupload@1.4
1.6.0

Open the chart page →

2,140
jenainseefrlab3.1.01 of 1See more

jena inseefrlab 3.1.0

1 of the 1 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
stain/jena-fuseki:latestb1d0c96f19ad
commons-fileupload2-core@2.0.0-M2
2.0.0-M4

Open the chart page →

1,262
openrefineinseefrlab3.5.01 of 1See more

openrefine inseefrlab 3.5.0

1 of the 1 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
easypi/openrefine:3.7.0d2950a36a576
commons-fileupload@1.4
1.6.0

Open the chart page →

1,754
jenkinsjenkins-x0.10.381 of 2See more

jenkins jenkins-x 0.10.38

1 of the 2 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
jenkinsci/jenkins:2.67a1f33f004659
commons-fileupload@1.3.1-jenkins-1
1.6.0

Open the chart page →

10,682
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
commons-fileupload@1.4
1.6.0

Open the chart page →

12,856
dinsrokronkltdVerified publisher0.1.71 of 2See more

dinsro kronkltd 0.1.7

1 of the 2 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
duck1123/dinsro:latest9568c5961d5d
commons-fileupload@1.4
1.6.0

Open the chart page →

1,628
penpotkubitodevVerified publisher1.2.11 of 5See more

penpot kubitodev 1.2.1

1 of the 5 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
commons-fileupload2-core@2.0.0-M1
2.0.0-M4

Open the chart page →

16,877
wiremocklebenitzaVerified publisher0.3.11 of 1See more

wiremock lebenitza 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.27.22328a9fce2bf
commons-fileupload@1.4
1.6.0

Open the chart page →

2,427
elastictranscoderluiscajl0.46.01 of 4See more

elastictranscoder luiscajl 0.46.0

1 of the 4 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
elastictranscoder/media-storage:f6d861a026208b8c2359
commons-fileupload@1.4
1.6.0

Open the chart page →

58,160
lavandaluiscajl0.0.1341 of 5See more

lavanda luiscajl 0.0.134

1 of the 5 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
lavandadelpatio/tmdb:0.0.2f36af885e915
commons-fileupload@1.4
1.6.0

Open the chart page →

18,248
tmdbluiscajl0.2.41 of 1See more

tmdb luiscajl 0.2.4

1 of the 1 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
lavandadelpatio/tmdb:latestded9377636e9
commons-fileupload@1.4
1.6.0

Open the chart page →

2,234
torznab-atomohdluiscajl0.0.31 of 1See more

torznab-atomohd luiscajl 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
lavandadelpatio/torznab-atomohd:latest214eaef5444c
commons-fileupload@1.4
1.6.0

Open the chart page →

3,290
metabase-k8smetabase-k8s1.0.01 of 1See more

metabase-k8s metabase-k8s 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
metabase/metabase:v0.53.4.17807bc5cad17
commons-fileupload2-core@2.0.0-M1
2.0.0-M4

Open the chart page →

2,589
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
commons-fileupload@1.5
1.6.0

Open the chart page →

3,683
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
commons-fileupload@1.5
1.6.0

Open the chart page →

5,129
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
commons-fileupload@1.3.3
1.6.0

Open the chart page →

43,341
crowdmoxVerified publisher2.4.31 of 3See more

crowd mox 2.4.3

1 of the 3 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
atlassian/crowd:5.2.2ebf761c7d437
commons-fileupload@1.5
1.6.0

Open the chart page →

5,663
devops-demomungari-development-charts1.0.41 of 4See more

devops-demo mungari-development-charts 1.0.4

1 of the 4 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
commons-fileupload@1.4
1.6.0

Open the chart page →

8,928
polyglotncsaVerified publisher0.1.114 of 18See more

polyglot ncsa 0.1.1

14 of the 18 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
commons-fileupload@1.3.1
1.6.0
ncsapolyglot/converters-avconv:latestc44b22eb58bb
commons-fileupload@1.3
1.6.0
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
commons-fileupload@1.3
1.6.0
ncsapolyglot/converters-ffmpeg:latest48c852c1204b
commons-fileupload@1.3
1.6.0
ncsapolyglot/converters-flac:latest072cf5bc6f99
commons-fileupload@1.3
1.6.0
ncsapolyglot/converters-gdal:latestf746049515c1
commons-fileupload@1.3
1.6.0
ncsapolyglot/converters-ghostscript:latestf350da56dd55
commons-fileupload@1.3
1.6.0
ncsapolyglot/converters-htmldoc:latest317dd9e56922
commons-fileupload@1.3
1.6.0
ncsapolyglot/converters-imagemagick:latestd244ea8c32ac
commons-fileupload@1.3
1.6.0
ncsapolyglot/converters-openjpeg:latest2ba4af461d51
commons-fileupload@1.3
1.6.0
ncsapolyglot/converters-txt2html:latest30ee96508c0b
commons-fileupload@1.3
1.6.0
ncsapolyglot/converters-unoconv:latest1d9cebe3022b
commons-fileupload@1.3
1.6.0
ncsapolyglot/converters-zip:latestf889fe30e2c7
commons-fileupload@1.3
1.6.0
ncsapolyglot/polyglot:2.4.097a8c01c076e
commons-fileupload@1.3
1.6.0

Open the chart page →

55,726
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
commons-fileupload@1.4
1.6.0

Open the chart page →

6,852
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
commons-fileupload2-core@2.0.0-M2
2.0.0-M4

Open the chart page →

5,826
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
commons-fileupload@1.5
1.6.0

Open the chart page →

6,037
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
commons-fileupload@1.4
1.6.0

Open the chart page →

12,927
voltha-infraopencord2.14.01 of 10See more

voltha-infra opencord 2.14.0

1 of the 10 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
voltha/voltha-onos:5.1.8e038acb950d3
commons-fileupload@1.4
1.6.0

Open the chart page →

41,044
canvas-oamportalopenshift4.0.01 of 1See more

canvas-oamportal openshift 4.0.0

1 of the 1 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
gurolakman/oam:4.0.0ed8fd2062548
commons-fileupload2-core@2.0.0-M2
2.0.0-M4

Open the chart page →

7,519
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
commons-fileupload@1.5
1.6.0

Open the chart page →

7,792
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
commons-fileupload@1.5
1.6.0

Open the chart page →

2,003
reportportalreportportal5.7.22 of 8See more

reportportal reportportal 5.7.2

2 of the 8 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
reportportal/service-api:5.7.29df41f8fb320
commons-fileupload@1.4
1.6.0
reportportal/service-authorization:5.7.09e73114dbd15
commons-fileupload@1.4
1.6.0

Open the chart page →

25,737
bastillion-upstreamrock8sVerified publisher0.1.01 of 1See more

bastillion-upstream rock8s 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
iamdorsah/bastillion:v0.1db83a0254d81
commons-fileupload@1.4
1.6.0

Open the chart page →

3,051
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
commons-fileupload@1.5
1.6.0

Open the chart page →

4,946
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
commons-fileupload@1.4
1.6.0

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
commons-fileupload@1.3.3
1.6.0

Open the chart page →

13,079
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
commons-fileupload@1.5
1.6.0

Open the chart page →

18,756
queryservicewbstack0.2.11 of 1See more

queryservice wbstack 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-48976.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice:0.3.6_0.6b83b5b81d4b6
commons-fileupload@1.3.3
1.6.0

Open the chart page →

4,649

Container images carrying it

110 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
metabase/metabase:v0.46.09ebdc664a6b2
commons-fileupload@1.5
1.6.0
1
metabase/metabase:v0.31.2ffb2dccacefc
commons-fileupload@1.3.3
1.6.0
1
mintproject/model-catalog-endpoint:29256555a6fbaefae4729d5cd259564708a4ab04ffbb13f20465
commons-fileupload@1.3.3
1.6.0
1
ncsapolyglot/converters-avconv:latestc44b22eb58bb
commons-fileupload@1.3
1.6.0
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
commons-fileupload@1.3
1.6.0
1
ncsapolyglot/converters-ffmpeg:latest48c852c1204b
commons-fileupload@1.3
1.6.0
1
ncsapolyglot/converters-flac:latest072cf5bc6f99
commons-fileupload@1.3
1.6.0
1
ncsapolyglot/converters-gdal:latestf746049515c1
commons-fileupload@1.3
1.6.0
1
ncsapolyglot/converters-ghostscript:latestf350da56dd55
commons-fileupload@1.3
1.6.0
1
ncsapolyglot/converters-htmldoc:latest317dd9e56922
commons-fileupload@1.3
1.6.0
1
ncsapolyglot/converters-imagemagick:latestd244ea8c32ac
commons-fileupload@1.3
1.6.0
1
ncsapolyglot/converters-openjpeg:latest2ba4af461d51
commons-fileupload@1.3
1.6.0
1
ncsapolyglot/converters-txt2html:latest30ee96508c0b
commons-fileupload@1.3
1.6.0
1
ncsapolyglot/converters-unoconv:latest1d9cebe3022b
commons-fileupload@1.3
1.6.0
1
ncsapolyglot/converters-zip:latestf889fe30e2c7
commons-fileupload@1.3
1.6.0
1
ncsapolyglot/polyglot:2.4.097a8c01c076e
commons-fileupload@1.3
1.6.0
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
commons-fileupload2-core@2.0.0-M2
2.0.0-M4
1
onosproject/onos:2.2.144914a8d4b3f
commons-fileupload@1.4
1.6.0
1
openkm/openkm-ce:6.3.113bc465a7461b
commons-fileupload@1.3.2
1.6.0
1
operaton/operaton:1.0.0-beta-4b35867ffe4d8
commons-fileupload@1.5
1.6.0
1
penpotapp/backend:2.2.147853d9bb9dd
commons-fileupload2-core@2.0.0-M1
2.0.0-M4
1
razzy10/product-service:latest702e411956db
commons-fileupload@1.5
1.6.0
1
reportportal/service-api:5.7.29df41f8fb320
commons-fileupload@1.4
1.6.0
1
reportportal/service-authorization:5.7.09e73114dbd15
commons-fileupload@1.4
1.6.0
1
rodolpheche/wiremock:2.27.22328a9fce2bf
commons-fileupload@1.4
1.6.0
1
rundeck/rundeck:3.2.74d64fe56f767
commons-fileupload@1.3.3
1.6.0
1
rundeck/rundeck:3.0.16b13e8059ad72
commons-fileupload@1.3.3
1.6.0
1
sonatype/nexus3:3.58.1586060431b64
commons-fileupload@1.5
1.6.0
1
stain/jena-fuseki:latestb1d0c96f19ad
commons-fileupload2-core@2.0.0-M2
2.0.0-M4
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
commons-fileupload@1.5
1.6.0
1
vitalii1992/account-service:latest0e694d94551d
commons-fileupload@1.4
1.6.0
1
vitalii1992/analytics-service:latest8e798836ecea
commons-fileupload@1.4
1.6.0
1
vitalii1992/api-gateway-service:latestaabe6ac39356
commons-fileupload@1.4
1.6.0
1
vitalii1992/order-service:latest07c4a8833ce4
commons-fileupload@1.4
1.6.0
1
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
commons-fileupload@1.4
1.6.0
1
vlebediantsev/logic-ms:latestdf8bf38c535b
commons-fileupload@1.4
1.6.0
1
voltha/voltha-onos:5.1.8e038acb950d3
commons-fileupload@1.4
1.6.0
1
vrijbrp/balie-ws:developc6603cb829ea
commons-fileupload@1.4
1.6.0
1
zenko/zenko-cosbench:0.0.6386a1f48ec0e
commons-fileupload@1.2.1
1.6.0
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
commons-fileupload@1.4
1.6.0
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
commons-fileupload@1.5
1.6.0
1
ghcr.io/gla-rad/enav-aton-admin-service:latestcf85570b1324
commons-fileupload@1.5
1.6.0
1
ghcr.io/gla-rad/enav-aton-service:latest3be878690629
commons-fileupload@1.5
1.6.0
1
ghcr.io/gla-rad/enav-aton-service-client:latestf1629ac5f9ec
commons-fileupload@1.5
1.6.0
1
ghcr.io/gla-rad/enav-ckeeper:latest415323ef112b
commons-fileupload@1.5
1.6.0
1
ghcr.io/gla-rad/enav-vdes-controller:latestc4c52955814f
commons-fileupload@1.5
1.6.0
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
commons-fileupload@1.4
1.6.0
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
commons-fileupload@1.4
1.6.0
1
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
commons-fileupload@1.4
1.6.0
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
commons-fileupload@1.4
1.6.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.