PT-2020-21450 · Npm · Express-Fileupload

Published

2020-09-03

·

Updated

2020-09-03

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions express-fileupload versions prior to 1.1.6-alpha.6
Description The issue causes server responses to be delayed, up to 30 seconds, when a request contains a large filename with . characters, leading to a Denial of Service.
Recommendations Upgrade to version 1.1.6-alpha.6 or later.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-Q3W9-G74Q-VP5F

Affected Products

Express-Fileupload