AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2016-3092

HIGH · CVSS 7.5 EPSS 35.93%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-07-04 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2016-3092
Severity
HIGH
CVSS
7.5
EPSS
35.93%
Apache

Original Filing — NVD Description

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.