GHSA-2g7p-5934-q4w7: Npm/payload vulnerability
Impact A malformed multipart request body could take an extremely long time to finish.
Patches Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34
Event History
Frequently Asked Questions
What must an attacker be able to do to exploit this issue?
An attacker needs to be able to send a malformed multipart request body to the affected Payload application.
What is the practical impact of a successful attack?
Processing the malformed multipart request can take an extremely long time to finish, potentially tying up application resources handling the request.
Which package versions contain the fix?
Upgrade the npm Payload package to version 3.90.0 or later, or to 4.0.0-canary.34 or later.