Disclosure summary
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
Source-reported weakness categories
CWE-264, CWE-835
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2014-0050
Open original source · Updated Oct 07, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| oracle | retail_applications | 12.0 |
| oracle | retail_applications | 12.0in |
| oracle | retail_applications | 13.0 |
| oracle | retail_applications | 13.1 |
| oracle | retail_applications | 13.2 |
| oracle | retail_applications | 13.3 |
| oracle | retail_applications | 13.4 |
| oracle | retail_applications | 14.0 |
| apache | commons_fileupload | * {"versionEndIncluding":"1.3"} |
| apache | commons_fileupload | 1.0 |
| apache | commons_fileupload | 1.1 |
| apache | commons_fileupload | 1.1.1 |
| apache | commons_fileupload | 1.2 |
| apache | commons_fileupload | 1.2.1 |
| apache | commons_fileupload | 1.2.2 |
| apache | tomcat | 7.0.0 |
| apache | tomcat | 7.0.0 |
| apache | tomcat | 7.0.1 |
| apache | tomcat | 7.0.2 |
| apache | tomcat | 7.0.2 |
| apache | tomcat | 7.0.3 |
| apache | tomcat | 7.0.4 |
| apache | tomcat | 7.0.4 |
| apache | tomcat | 7.0.5 |
| apache | tomcat | 7.0.6 |
| apache | tomcat | 7.0.7 |
| apache | tomcat | 7.0.8 |
| apache | tomcat | 7.0.9 |
| apache | tomcat | 7.0.10 |
| apache | tomcat | 7.0.11 |
| apache | tomcat | 7.0.12 |
| apache | tomcat | 7.0.13 |
| apache | tomcat | 7.0.14 |
| apache | tomcat | 7.0.15 |
| apache | tomcat | 7.0.16 |
| apache | tomcat | 7.0.17 |
| apache | tomcat | 7.0.18 |
| apache | tomcat | 7.0.19 |
| apache | tomcat | 7.0.20 |
| apache | tomcat | 7.0.21 |
| apache | tomcat | 7.0.22 |
| apache | tomcat | 7.0.23 |
| apache | tomcat | 7.0.24 |
| apache | tomcat | 7.0.25 |
| apache | tomcat | 7.0.26 |
| apache | tomcat | 7.0.27 |
| apache | tomcat | 7.0.28 |
| apache | tomcat | 7.0.29 |
| apache | tomcat | 7.0.30 |
| apache | tomcat | 7.0.31 |
| apache | tomcat | 7.0.32 |
| apache | tomcat | 7.0.33 |
| apache | tomcat | 7.0.34 |
| apache | tomcat | 7.0.35 |
| apache | tomcat | 7.0.36 |
| apache | tomcat | 7.0.37 |
| apache | tomcat | 7.0.38 |
| apache | tomcat | 7.0.39 |
| apache | tomcat | 7.0.40 |
| apache | tomcat | 7.0.41 |
| apache | tomcat | 7.0.42 |
| apache | tomcat | 7.0.43 |
| apache | tomcat | 7.0.44 |
| apache | tomcat | 7.0.45 |
| apache | tomcat | 7.0.46 |
| apache | tomcat | 7.0.47 |
| apache | tomcat | 7.0.48 |
| apache | tomcat | 7.0.49 |
| apache | tomcat | 7.0.50 |
| apache | tomcat | 8.0.0 |
| apache | tomcat | 8.0.0 |
| apache | tomcat | 8.0.0 |
| apache | tomcat | 8.0.0 |
| apache | tomcat | 8.0.1 |
Original records & references
- NIST NVD record
- CVE Program record
- bugzilla.redhat.com
- h20566.www2.hpe.com
- h20566.www2.hpe.com
- h20566.www2.hpe.com
- security.gentoo.org
- bugzilla.redhat.com
- h20566.www2.hpe.com
- h20566.www2.hpe.com
- h20566.www2.hpe.com
- security.gentoo.org
PUBLISHED 2014-04-01T02:27:51-04:00
MODIFIED 2026-10-07T14:17:05-04:00
INGESTED 2026-10-08T12:30:34-04:00