CVE-2026-105854: Payload: ReDoS in Multipart Content-Type Validation
Impact A malformed multipart request body could take an extremely long time to finish.
Patches Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Other sources
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, a malformed multipart request body can cause multipart Content-Type processing to take an extremely long time, resulting in uncontrolled resource consumption. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34
Event History
Frequently Asked Questions
Which deployments are affected?
Payload versions from 3.0.0 before 3.90.0 are affected, as are canary releases before 4.0.0-canary.34.
What does an attacker need to do to trigger the issue?
An attacker can send a malformed multipart request body. The supplied CVSS vector indicates network-based exploitation with no privileges or user interaction required.
What is the practical impact?
Processing the multipart Content-Type can take an extremely long time, causing uncontrolled resource consumption and affecting availability.
Which versions contain the fix?
Upgrade to Payload 3.90.0 or later, or to 4.0.0-canary.34 or later for the canary line.