PT-2026-39996 · Npm · Multipart
Aszx87410
+2
·
Published
2026-05-12
·
Updated
2026-05-18
·
CVE-2026-8159
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
multiparty versions prior to 4.3.0
Description
A denial of service issue exists due to regular expression backtracking in the Content-Disposition filename parameter parser. A crafted multipart upload containing a long header value can cause regex matching to take several seconds, which blocks the event loop. This affects any service that accepts multipart uploads using this library.
Recommendations
Upgrade to version 4.3.0 or higher.
Limit upload sizes at the proxy or gateway layer to reduce the attack surface.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Multipart