Skip to main content
ruslanr63825226
Participant
January 9, 2026
Question

Coldfusion 2023 Fileupload-1.5.jar Vulnerability

  • January 9, 2026
  • 1 reply
  • 190 views

Tenable Security scan has identified Fileupload-1.5.jar as a high Vulnerability. Is this a false positive ? 

C:\ColdFusion2023\bundles\repo\commons-fileupload-1.5.jar Installed version : 1.5 Fixed version : 1.6 Path : C:\ColdFusion2023\bundles\updateinstallers\hotfix-packages-cf2023-016-330828\repo\commons-fileupload-1.5.jar Installed version : 1.5 Fixed version : 1.6 Path : C:\ColdFusion2023\bundles\updateinstallers\hotfix-packages-cf2023-016-330828\repo\commons-fileupload-1.4.jar Installed version : 1.4 Fixed version : 1.6 Path : C:\ColdFusion2023\cfusion\lib\bundleaxis\commons-fileupload-1.5.jar Installed version : 1.5 Fixed version : 1.6 Path :

    1 reply

    BKBK
    Community Expert
    Community Expert
    January 10, 2026

    Hi @ruslanr63825226 , thanks for sharing that.

     

    It is an important alert. I have therefore created a bug ticket requesting a fix.

    ruslanr63825226
    Participant
    January 20, 2026

    Coldfusion 23 hotfix 18 did not resolve the issue. Typically never had to update files within ColdFusion directories in the past unless it was a hotfix provided by Adobe. 

    BKBK
    Community Expert
    Community Expert
    January 20, 2026

    I think we should give Adobe some time to work on a fix.