PT-2025-1271 · Fastify · Fastify-Multipart

Mcollina

·

Published

2025-01-23

·

Updated

2025-01-23

·

CVE-2025-24033

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions @fastify/multipart versions prior to 8.3.1 and 9.0.3
Description The issue is related to the saveRequestFiles function in the @fastify/multipart plugin for Fastify, which fails to delete uploaded temporary files when a user cancels a request. This can be exploited by a remote attacker to cause a denial of service by sending a specially crafted request. The problem is caused by the incorrect handling of authentication tokens due to unlimited resource allocation.
Recommendations For versions prior to 8.3.1, update to version 8.3.1 or later. For versions prior to 9.0.3, update to version 9.0.3 or later. As a temporary workaround, do not use the saveRequestFiles function until a patch is applied.

Exploit

Fix

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2025-00720
CVE-2025-24033
GHSA-27C6-MCXV-X3FH

Affected Products

Fastify-Multipart