Multiple CVEs are published against commons-fileupload 1.3.1. - https://nvd.nist.gov/vuln/detail/CVE-2016-1000031 - https://nvd.nist.gov/vuln/detail/CVE-2016-3092 These have both been resolved in commons-fileupload 1.3.3