VDB
Sign up
—

EEF-CVE-2026-56814

Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)

Quick fix

EEF-CVE-2026-56814 — plug: upgrade to the fixed version with the command below.

mix deps.update plug

Details

## Summary

`Plug.Parsers.MULTIPART`, the multipart request-body parser used to handle file uploads and multipart forms, does not enforce its `:length` budget against all consumed resources, allowing an unauthenticated remote attacker to cause denial of service. The parser charges the `:length` limit only for part body bytes; part header bytes are never counted, and a part with an empty body costs zero.

Because every part whose `Content-Disposition` carries a non-empty `filename` creates a fresh temporary file (via `Plug.Upload`) and retains a `Plug.Upload` struct for the duration of the request, an attacker can send a single request composed of many empty-body file parts. Such a request stays well under the configured `:length` limit (8,000,000 bytes by default) while creating one temporary file per part, leading to inode and disk exhaustion and unbounded memory growth. Any application using `Plug.Parsers` with the `:multipart` parser is affected, and no authentication is required, only reachability of a multipart endpoint over HTTP.

This vulnerability is associated with program files `lib/plug/parsers/multipart.ex` and program routines `Plug.Parsers.MULTIPART.parse_multipart/2`, `Plug.Parsers.MULTIPART.parse_multipart_headers/5`, `Plug.Parsers.MULTIPART.parse_multipart_body/4`, and `Plug.Parsers.MULTIPART.parse_multipart_file/4`.

This issue affects plug: from 1.4.0-rc.0 before 1.16.6, from 1.17.0 before 1.17.4, from 1.18.0 before 1.18.5, from 1.19.1 before 1.19.5, and from 1.20.0 before 1.20.3.

Are you affected?

Enter the version of the package you're using.

Affected packages

Hex/plug
Introduced in: 1.4.0-rc.0Fixed in: 1.16.6
Fixmix deps.update plug

References